Designing Access Controls
Finalize Security Policies
Table 3-98. Macro Security Tests
| Microsoft Excel | Microsoft Outlook | Microsoft Word |
| |||
Security | High | Medium | High | Medium | High |
| Medium |
setting | Low |
| Low |
| Low |
|
|
|
|
|
|
|
|
|
|
5.Does your organization prohibit
When you activate the P2P test, it prohibits all P2P applications. But you can then choose specific ones to allow in your network. List the excep- tions for this test in Table
6.Do your users run Microsoft Virtual Machine (MVM)? If so, do you require hotfixes?
7.Do your users run Windows Media Player? If so, do you require hotfixes?
8.Do your users run Mac QuickTime? If so, do you require hotfixes?
9.Do you test the compliance of your Microsoft Internet Information Ser- vices (IIS) server?
Table 3-99. Other Tests for Hotfixes
MVM | Windows Media Mac QuickTime IIS |
| Player |
|
|
Hotfixes required?
10.Does your policy specify a particular setting for Windows automatic updates?
If so, you should enable this test and choose one of the options displayed in Table
If you are afraid that users might choose not to download and install updates, you might require the “automatically download and install” option. On the other hand, if you have your own process for distributing updates, you might want to turn off automatic updates.