Adobe Acrobat Pro DC STIG
18 items · Security · Medium difficulty · 2 hours
Harden Acrobat Pro DC using DISA STIG guidance for Windows-managed environments.
-
Download STIG resources
Gather DISA-authorized STIG files before configuring systems.
-
Download SCAP 1.3 content for Acrobat Pro DC
Get the SCAP content (DISA) matching Ver 2, Rel 1 for automated scanning.
-
Download standalone XCCDF benchmark for the STIG
Obtain the XCCDF 1.1.4 file to drive compliance checks and scanners.
-
Download latest GPO and Intune policy packages
Fetch the GPOs and Intune policies from DISA to apply recommended settings.
-
Verify Acrobat Pro DC version and installation type
Confirm continuous-track build and whether install is default or custom.
-
Backup current Acrobat configuration and create a system restore point
Save registry/app settings to revert if hardening breaks functionality.
-
Apply latest Acrobat updates and security patches
Install vendor patches before making configuration changes.
-
Disable JavaScript in Acrobat
Turn off or restrict JavaScript execution to reduce attack surface.
-
Enable Protected View for files from potentially unsafe locations
Set Protected View to open untrusted files in a sandboxed reader.
-
Enable Protected Mode (sandbox) for Acrobat
Ensure the process sandbox is active to limit file/process access.
-
Disable or restrict embedded file execution and launch privileges
Prevent PDFs from launching external applications or embedded executables.
-
Configure update settings to auto-check and install security updates
Set automatic updates or scheduled checks to maintain patch currency.
-
Apply Group Policy Objects (GPOs) to managed systems
Import and link the downloaded GPOs to enforce STIG settings domain-wide.
-
Import Intune policies to managed endpoints
Deploy Intune policy packages for cloud-managed devices.
-
Test all changes in a representative test environment
Validate functionality and user workflows before wide deployment.
-
Document configuration changes, versions, and implementation notes
Record applied settings, timestamps, and rollback steps for audits.
-
Subscribe to DISA and vendor security update feeds and monitor CVEs
Track advisories to update policies and address new vulnerabilities.
-
Send feedback or change requests to DISA
Email DISA Field Security Operations at [email protected] with comments.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.