<?xml version="1.0" encoding="UTF-8"?>
<Benchmark id="fdcc-ie-7" resolved="0" xml:lang="en"
      xmlns="http://checklists.nist.gov/xccdf/1.1"
      xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
      xmlns:cdf="http://checklists.nist.gov/xccdf/1.1"
      xmlns:cpe="http://cpe.mitre.org/dictionary/2.0"
      xmlns:dc="http://purl.org/dc/elements/1.1/"
      xmlns:xhtml="http://www.w3.org/1999/xhtml"
      xmlns:dsig="http://www.w3.org/2000/09/xmldsig#"
      xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.1 http://nvd.nist.gov/schema/xccdf-1.1.4.xsd
      http://cpe.mitre.org/dictionary/2.0 http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
      <status date="2009-04-08">accepted</status>
      <title>FDCC: Guidance for Securing Microsoft Internet Explorer 7 for IT Professionals</title>
      <description>This guide has been created to assist IT professionals in effectively securing systems with Microsoft Internet Explorer 7 installed.</description>
      <notice id="terms-of-use" xml:lang="en">Do not attempt to implement any of the settings in this guide without first testing them in a non-operational environment. NIST assumes no responsibility whatsoever for its use by other parties, and makes no guarantees, expressed or implied, about its quality, reliability, or any other characteristic. NIST would appreciate acknowledgement if the document and template are used.</notice>
      <front-matter xml:lang="en">todo - add text</front-matter>
      <rear-matter xml:lang="en"><xhtml:strong>Trademark Information</xhtml:strong><xhtml:br/><xhtml:br/>Microsoft, Windows, Windows XP, Windows Vista, Internet Explorer, and Windows Firewall are either registered trademarks or trademarks of Microsoft Corporation in the United States and other countries.<xhtml:br/><xhtml:br/>All other names are registered trademarks or trademarks of their respective companies.</rear-matter>
      <reference href="http://nvd.nist.gov/chklst_detail.cfm?config_id=76">
            <dc:publisher>National Institute of Standards and Technology</dc:publisher>
            <dc:identifier>SP 800-68</dc:identifier>
      </reference>
      <platform idref="cpe:/a:microsoft:ie:7"/>
      <version>v1.2.0.0</version>
      <model system="urn:xccdf:scoring:default"/>
      <model system="urn:xccdf:scoring:flat"/>
      <!-- ==================================================================================================== -->
      <!-- ======================================  NIST 800-53 PROFILES  ====================================== -->
      <!-- ==================================================================================================== -->
      <!--                                                                                                      -->
      <!-- The following profiles are used to turn on specific controls as definied in 800-53.  These controls  -->
      <!-- help determine the specific rules that will be evaluated as certain rules found in this document     -->
      <!-- require specific controls to be enabled.  This enable FISMA compliance to be achived by combining    -->
      <!-- guidance defined with high level recommendations made in 800-53.                                     -->
      <!--                                                                                                      -->
      <Profile id="low_800_53" abstract="true">
            <title>800-53 Low</title>
            <description>This profile selects specific controls that are recommended by Special Publication 800-53 for information systems in which all three security objectives (i.e., confidentiality, integrity, and availability) are assigned a FIPS 199 potential impact value of low. Each control has an effect on other groups within this document as individual rule require certain controls to be selected.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AC-1" selected="true"/>
            <select idref="AC-2" selected="true"/>
            <select idref="AC-3" selected="true"/>
            <select idref="AC-4" selected="false"/>
            <select idref="AC-5" selected="false"/>
            <select idref="AC-6" selected="false"/>
            <select idref="AC-7" selected="true"/>
            <select idref="AC-8" selected="true"/>
            <select idref="AC-9" selected="false"/>
            <select idref="AC-10" selected="false"/>
            <select idref="AC-11" selected="false"/>
            <select idref="AC-12" selected="false"/>
            <select idref="AC-13" selected="true"/>
            <select idref="AC-14" selected="true"/>
            <select idref="AC-15" selected="false"/>
            <select idref="AC-16" selected="false"/>
            <select idref="AC-17" selected="true"/>
            <select idref="AC-18" selected="false"/>
            <select idref="AC-19" selected="false"/>
            <select idref="AC-20" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AT  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AT-1" selected="true"/>
            <select idref="AT-2" selected="true"/>
            <select idref="AT-3" selected="true"/>
            <select idref="AT-4" selected="true"/>
            <select idref="AT-5" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AU  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AU-1" selected="true"/>
            <select idref="AU-2" selected="true"/>
            <select idref="AU-3" selected="true"/>
            <select idref="AU-4" selected="true"/>
            <select idref="AU-5" selected="true"/>
            <select idref="AU-6" selected="false"/>
            <select idref="AU-7" selected="false"/>
            <select idref="AU-8" selected="false"/>
            <select idref="AU-9" selected="true"/>
            <select idref="AU-10" selected="false"/>
            <select idref="AU-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CA-1" selected="true"/>
            <select idref="CA-2" selected="false"/>
            <select idref="CA-3" selected="true"/>
            <select idref="CA-4" selected="true"/>
            <select idref="CA-5" selected="true"/>
            <select idref="CA-6" selected="true"/>
            <select idref="CA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CM  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CM-1" selected="true"/>
            <select idref="CM-2" selected="true"/>
            <select idref="CM-3" selected="false"/>
            <select idref="CM-4" selected="false"/>
            <select idref="CM-5" selected="false"/>
            <select idref="CM-6" selected="true"/>
            <select idref="CM-7" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CP-1" selected="true"/>
            <select idref="CP-2" selected="true"/>
            <select idref="CP-3" selected="false"/>
            <select idref="CP-4" selected="false"/>
            <select idref="CP-5" selected="true"/>
            <select idref="CP-6" selected="false"/>
            <select idref="CP-7" selected="false"/>
            <select idref="CP-8" selected="false"/>
            <select idref="CP-9" selected="true"/>
            <select idref="CP-10" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IA-1" selected="true"/>
            <select idref="IA-2" selected="true"/>
            <select idref="IA-3" selected="false"/>
            <select idref="IA-4" selected="true"/>
            <select idref="IA-5" selected="true"/>
            <select idref="IA-6" selected="true"/>
            <select idref="IA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IR  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IR-1" selected="true"/>
            <select idref="IR-2" selected="false"/>
            <select idref="IR-3" selected="false"/>
            <select idref="IR-4" selected="true"/>
            <select idref="IR-5" selected="false"/>
            <select idref="IR-6" selected="true"/>
            <select idref="IR-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MA-1" selected="true"/>
            <select idref="MA-2" selected="true"/>
            <select idref="MA-3" selected="false"/>
            <select idref="MA-4" selected="true"/>
            <select idref="MA-5" selected="true"/>
            <select idref="MA-6" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MP-1" selected="true"/>
            <select idref="MP-2" selected="true"/>
            <select idref="MP-3" selected="false"/>
            <select idref="MP-4" selected="false"/>
            <select idref="MP-5" selected="false"/>
            <select idref="MP-6" selected="false"/>
            <select idref="MP-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PE  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PE-1" selected="true"/>
            <select idref="PE-2" selected="true"/>
            <select idref="PE-3" selected="true"/>
            <select idref="PE-4" selected="false"/>
            <select idref="PE-5" selected="false"/>
            <select idref="PE-6" selected="true"/>
            <select idref="PE-7" selected="true"/>
            <select idref="PE-8" selected="true"/>
            <select idref="PE-9" selected="false"/>
            <select idref="PE-10" selected="false"/>
            <select idref="PE-11" selected="false"/>
            <select idref="PE-12" selected="true"/>
            <select idref="PE-13" selected="true"/>
            <select idref="PE-14" selected="true"/>
            <select idref="PE-15" selected="true"/>
            <select idref="PE-16" selected="true"/>
            <select idref="PE-17" selected="false"/>
            <select idref="PE-18" selected="false"/>
            <select idref="PE-19" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PL  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PL-1" selected="true"/>
            <select idref="PL-2" selected="true"/>
            <select idref="PL-3" selected="true"/>
            <select idref="PL-4" selected="true"/>
            <select idref="PL-5" selected="true"/>
            <select idref="PL-6" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PS  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PS-1" selected="true"/>
            <select idref="PS-2" selected="true"/>
            <select idref="PS-3" selected="true"/>
            <select idref="PS-4" selected="true"/>
            <select idref="PS-5" selected="true"/>
            <select idref="PS-6" selected="true"/>
            <select idref="PS-7" selected="true"/>
            <select idref="PS-8" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  RA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="RA-1" selected="true"/>
            <select idref="RA-2" selected="true"/>
            <select idref="RA-3" selected="true"/>
            <select idref="RA-4" selected="true"/>
            <select idref="RA-5" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SA-1" selected="true"/>
            <select idref="SA-2" selected="true"/>
            <select idref="SA-3" selected="true"/>
            <select idref="SA-4" selected="true"/>
            <select idref="SA-5" selected="true"/>
            <select idref="SA-6" selected="true"/>
            <select idref="SA-7" selected="true"/>
            <select idref="SA-8" selected="false"/>
            <select idref="SA-9" selected="true"/>
            <select idref="SA-10" selected="false"/>
            <select idref="SA-11" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SC-1" selected="true"/>
            <select idref="SC-2" selected="false"/>
            <select idref="SC-3" selected="false"/>
            <select idref="SC-4" selected="false"/>
            <select idref="SC-5" selected="true"/>
            <select idref="SC-6" selected="false"/>
            <select idref="SC-7" selected="true"/>
            <select idref="SC-8" selected="false"/>
            <select idref="SC-9" selected="false"/>
            <select idref="SC-10" selected="false"/>
            <select idref="SC-11" selected="false"/>
            <select idref="SC-12" selected="false"/>
            <select idref="SC-13" selected="true"/>
            <select idref="SC-14" selected="true"/>
            <select idref="SC-15" selected="false"/>
            <select idref="SC-16" selected="false"/>
            <select idref="SC-17" selected="false"/>
            <select idref="SC-18" selected="false"/>
            <select idref="SC-19" selected="false"/>
            <select idref="SC-20" selected="false"/>
            <select idref="SC-21" selected="false"/>
            <select idref="SC-22" selected="false"/>
            <select idref="SC-23" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SI  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SI-1" selected="true"/>
            <select idref="SI-2" selected="true"/>
            <select idref="SI-3" selected="true"/>
            <select idref="SI-4" selected="false"/>
            <select idref="SI-5" selected="true"/>
            <select idref="SI-6" selected="false"/>
            <select idref="SI-7" selected="false"/>
            <select idref="SI-8" selected="false"/>
            <select idref="SI-9" selected="false"/>
            <select idref="SI-10" selected="false"/>
            <select idref="SI-11" selected="false"/>
            <select idref="SI-12" selected="false"/>
      </Profile>
      <Profile id="moderate_800_53" abstract="true">
            <title>800-53 Moderate</title>
            <description>This profile selects specific controls that are recommended by Special Publication 800-53 for information systems in which at least one security objectives (i.e., confidentiality, integrity, and availability) are assigned a FIPS 199 potential impact value of moderate and no security objective is assigned a FIPS 199 potential impact value of high. Each control has an effect on other groups within this document as individual rule require certain controls to be selected.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AC-1" selected="true"/>
            <select idref="AC-2" selected="true"/>
            <select idref="AC-3" selected="true"/>
            <select idref="AC-4" selected="true"/>
            <select idref="AC-5" selected="true"/>
            <select idref="AC-6" selected="true"/>
            <select idref="AC-7" selected="true"/>
            <select idref="AC-8" selected="true"/>
            <select idref="AC-9" selected="false"/>
            <select idref="AC-10" selected="false"/>
            <select idref="AC-11" selected="true"/>
            <select idref="AC-12" selected="true"/>
            <select idref="AC-13" selected="true"/>
            <select idref="AC-14" selected="true"/>
            <select idref="AC-15" selected="false"/>
            <select idref="AC-16" selected="false"/>
            <select idref="AC-17" selected="true"/>
            <select idref="AC-18" selected="true"/>
            <select idref="AC-19" selected="true"/>
            <select idref="AC-20" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AT  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AT-1" selected="true"/>
            <select idref="AT-2" selected="true"/>
            <select idref="AT-3" selected="true"/>
            <select idref="AT-4" selected="true"/>
            <select idref="AT-5" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AU  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AU-1" selected="true"/>
            <select idref="AU-2" selected="true"/>
            <select idref="AU-3" selected="true"/>
            <select idref="AU-4" selected="true"/>
            <select idref="AU-5" selected="true"/>
            <select idref="AU-6" selected="true"/>
            <select idref="AU-7" selected="true"/>
            <select idref="AU-8" selected="true"/>
            <select idref="AU-9" selected="true"/>
            <select idref="AU-10" selected="false"/>
            <select idref="AU-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CA-1" selected="true"/>
            <select idref="CA-2" selected="true"/>
            <select idref="CA-3" selected="true"/>
            <select idref="CA-4" selected="true"/>
            <select idref="CA-5" selected="true"/>
            <select idref="CA-6" selected="true"/>
            <select idref="CA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CM  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CM-1" selected="true"/>
            <select idref="CM-2" selected="true"/>
            <select idref="CM-3" selected="true"/>
            <select idref="CM-4" selected="true"/>
            <select idref="CM-5" selected="true"/>
            <select idref="CM-6" selected="true"/>
            <select idref="CM-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CP-1" selected="true"/>
            <select idref="CP-2" selected="true"/>
            <select idref="CP-3" selected="true"/>
            <select idref="CP-4" selected="true"/>
            <select idref="CP-5" selected="true"/>
            <select idref="CP-6" selected="true"/>
            <select idref="CP-7" selected="true"/>
            <select idref="CP-8" selected="true"/>
            <select idref="CP-9" selected="true"/>
            <select idref="CP-10" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IA-1" selected="true"/>
            <select idref="IA-2" selected="true"/>
            <select idref="IA-3" selected="true"/>
            <select idref="IA-4" selected="true"/>
            <select idref="IA-5" selected="true"/>
            <select idref="IA-6" selected="true"/>
            <select idref="IA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IR  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IR-1" selected="true"/>
            <select idref="IR-2" selected="true"/>
            <select idref="IR-3" selected="true"/>
            <select idref="IR-4" selected="true"/>
            <select idref="IR-5" selected="true"/>
            <select idref="IR-6" selected="true"/>
            <select idref="IR-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MA-1" selected="true"/>
            <select idref="MA-2" selected="true"/>
            <select idref="MA-3" selected="true"/>
            <select idref="MA-4" selected="true"/>
            <select idref="MA-5" selected="true"/>
            <select idref="MA-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MP-1" selected="true"/>
            <select idref="MP-2" selected="true"/>
            <select idref="MP-3" selected="true"/>
            <select idref="MP-4" selected="true"/>
            <select idref="MP-5" selected="true"/>
            <select idref="MP-6" selected="true"/>
            <select idref="MP-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PE  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PE-1" selected="true"/>
            <select idref="PE-2" selected="true"/>
            <select idref="PE-3" selected="true"/>
            <select idref="PE-4" selected="false"/>
            <select idref="PE-5" selected="true"/>
            <select idref="PE-6" selected="true"/>
            <select idref="PE-7" selected="true"/>
            <select idref="PE-8" selected="true"/>
            <select idref="PE-9" selected="true"/>
            <select idref="PE-10" selected="true"/>
            <select idref="PE-11" selected="true"/>
            <select idref="PE-12" selected="true"/>
            <select idref="PE-13" selected="true"/>
            <select idref="PE-14" selected="true"/>
            <select idref="PE-15" selected="true"/>
            <select idref="PE-16" selected="true"/>
            <select idref="PE-17" selected="true"/>
            <select idref="PE-18" selected="true"/>
            <select idref="PE-19" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PL  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PL-1" selected="true"/>
            <select idref="PL-2" selected="true"/>
            <select idref="PL-3" selected="true"/>
            <select idref="PL-4" selected="true"/>
            <select idref="PL-5" selected="true"/>
            <select idref="PL-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PS  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PS-1" selected="true"/>
            <select idref="PS-2" selected="true"/>
            <select idref="PS-3" selected="true"/>
            <select idref="PS-4" selected="true"/>
            <select idref="PS-5" selected="true"/>
            <select idref="PS-6" selected="true"/>
            <select idref="PS-7" selected="true"/>
            <select idref="PS-8" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  RA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="RA-1" selected="true"/>
            <select idref="RA-2" selected="true"/>
            <select idref="RA-3" selected="true"/>
            <select idref="RA-4" selected="true"/>
            <select idref="RA-5" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SA-1" selected="true"/>
            <select idref="SA-2" selected="true"/>
            <select idref="SA-3" selected="true"/>
            <select idref="SA-4" selected="true"/>
            <select idref="SA-5" selected="true"/>
            <select idref="SA-6" selected="true"/>
            <select idref="SA-7" selected="true"/>
            <select idref="SA-8" selected="false"/>
            <select idref="SA-9" selected="true"/>
            <select idref="SA-10" selected="false"/>
            <select idref="SA-11" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SC-1" selected="true"/>
            <select idref="SC-2" selected="true"/>
            <select idref="SC-3" selected="false"/>
            <select idref="SC-4" selected="true"/>
            <select idref="SC-5" selected="true"/>
            <select idref="SC-6" selected="true"/>
            <select idref="SC-7" selected="true"/>
            <select idref="SC-8" selected="true"/>
            <select idref="SC-9" selected="true"/>
            <select idref="SC-10" selected="true"/>
            <select idref="SC-11" selected="false"/>
            <select idref="SC-12" selected="true"/>
            <select idref="SC-13" selected="true"/>
            <select idref="SC-14" selected="true"/>
            <select idref="SC-15" selected="true"/>
            <select idref="SC-16" selected="false"/>
            <select idref="SC-17" selected="true"/>
            <select idref="SC-18" selected="true"/>
            <select idref="SC-19" selected="true"/>
            <select idref="SC-20" selected="true"/>
            <select idref="SC-21" selected="false"/>
            <select idref="SC-22" selected="true"/>
            <select idref="SC-23" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SI  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SI-1" selected="true"/>
            <select idref="SI-2" selected="true"/>
            <select idref="SI-3" selected="true"/>
            <select idref="SI-4" selected="true"/>
            <select idref="SI-5" selected="true"/>
            <select idref="SI-6" selected="true"/>
            <select idref="SI-7" selected="false"/>
            <select idref="SI-8" selected="true"/>
            <select idref="SI-9" selected="true"/>
            <select idref="SI-10" selected="true"/>
            <select idref="SI-11" selected="true"/>
            <select idref="SI-12" selected="true"/>
      </Profile>
      <Profile id="high_800_53" abstract="true">
            <title>800-53 High</title>
            <description>This profile selects specific controls that are recommended by Special Publication 800-53 for information systems in which at least one security objectives (i.e., confidentiality, integrity, and availability) are assigned a FIPS 199 potential impact value of high. Each control has an effect on other groups within this document as individual rule require certain controls to be selected.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AC-1" selected="true"/>
            <select idref="AC-2" selected="true"/>
            <select idref="AC-3" selected="true"/>
            <select idref="AC-4" selected="true"/>
            <select idref="AC-5" selected="true"/>
            <select idref="AC-6" selected="true"/>
            <select idref="AC-7" selected="true"/>
            <select idref="AC-8" selected="true"/>
            <select idref="AC-9" selected="false"/>
            <select idref="AC-10" selected="true"/>
            <select idref="AC-11" selected="true"/>
            <select idref="AC-12" selected="true"/>
            <select idref="AC-13" selected="true"/>
            <select idref="AC-14" selected="true"/>
            <select idref="AC-15" selected="true"/>
            <select idref="AC-16" selected="false"/>
            <select idref="AC-17" selected="true"/>
            <select idref="AC-18" selected="true"/>
            <select idref="AC-19" selected="true"/>
            <select idref="AC-20" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AT  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AT-1" selected="true"/>
            <select idref="AT-2" selected="true"/>
            <select idref="AT-3" selected="true"/>
            <select idref="AT-4" selected="true"/>
            <select idref="AT-5" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AU  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AU-1" selected="true"/>
            <select idref="AU-2" selected="true"/>
            <select idref="AU-3" selected="true"/>
            <select idref="AU-4" selected="true"/>
            <select idref="AU-5" selected="true"/>
            <select idref="AU-6" selected="true"/>
            <select idref="AU-7" selected="true"/>
            <select idref="AU-8" selected="true"/>
            <select idref="AU-9" selected="true"/>
            <select idref="AU-10" selected="false"/>
            <select idref="AU-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CA-1" selected="true"/>
            <select idref="CA-2" selected="true"/>
            <select idref="CA-3" selected="true"/>
            <select idref="CA-4" selected="true"/>
            <select idref="CA-5" selected="true"/>
            <select idref="CA-6" selected="true"/>
            <select idref="CA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CM  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CM-1" selected="true"/>
            <select idref="CM-2" selected="true"/>
            <select idref="CM-3" selected="true"/>
            <select idref="CM-4" selected="true"/>
            <select idref="CM-5" selected="true"/>
            <select idref="CM-6" selected="true"/>
            <select idref="CM-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CP-1" selected="true"/>
            <select idref="CP-2" selected="true"/>
            <select idref="CP-3" selected="true"/>
            <select idref="CP-4" selected="true"/>
            <select idref="CP-5" selected="true"/>
            <select idref="CP-6" selected="true"/>
            <select idref="CP-7" selected="true"/>
            <select idref="CP-8" selected="true"/>
            <select idref="CP-9" selected="true"/>
            <select idref="CP-10" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IA-1" selected="true"/>
            <select idref="IA-2" selected="true"/>
            <select idref="IA-3" selected="true"/>
            <select idref="IA-4" selected="true"/>
            <select idref="IA-5" selected="true"/>
            <select idref="IA-6" selected="true"/>
            <select idref="IA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IR  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IR-1" selected="true"/>
            <select idref="IR-2" selected="true"/>
            <select idref="IR-3" selected="true"/>
            <select idref="IR-4" selected="true"/>
            <select idref="IR-5" selected="true"/>
            <select idref="IR-6" selected="true"/>
            <select idref="IR-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MA-1" selected="true"/>
            <select idref="MA-2" selected="true"/>
            <select idref="MA-3" selected="true"/>
            <select idref="MA-4" selected="true"/>
            <select idref="MA-5" selected="true"/>
            <select idref="MA-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MP-1" selected="true"/>
            <select idref="MP-2" selected="true"/>
            <select idref="MP-3" selected="true"/>
            <select idref="MP-4" selected="true"/>
            <select idref="MP-5" selected="true"/>
            <select idref="MP-6" selected="true"/>
            <select idref="MP-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PE  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PE-1" selected="true"/>
            <select idref="PE-2" selected="true"/>
            <select idref="PE-3" selected="true"/>
            <select idref="PE-4" selected="false"/>
            <select idref="PE-5" selected="true"/>
            <select idref="PE-6" selected="true"/>
            <select idref="PE-7" selected="true"/>
            <select idref="PE-8" selected="true"/>
            <select idref="PE-9" selected="true"/>
            <select idref="PE-10" selected="true"/>
            <select idref="PE-11" selected="true"/>
            <select idref="PE-12" selected="true"/>
            <select idref="PE-13" selected="true"/>
            <select idref="PE-14" selected="true"/>
            <select idref="PE-15" selected="true"/>
            <select idref="PE-16" selected="true"/>
            <select idref="PE-17" selected="true"/>
            <select idref="PE-18" selected="true"/>
            <select idref="PE-19" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PL  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PL-1" selected="true"/>
            <select idref="PL-2" selected="true"/>
            <select idref="PL-3" selected="true"/>
            <select idref="PL-4" selected="true"/>
            <select idref="PL-5" selected="true"/>
            <select idref="PL-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PS  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PS-1" selected="true"/>
            <select idref="PS-2" selected="true"/>
            <select idref="PS-3" selected="true"/>
            <select idref="PS-4" selected="true"/>
            <select idref="PS-5" selected="true"/>
            <select idref="PS-6" selected="true"/>
            <select idref="PS-7" selected="true"/>
            <select idref="PS-8" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  RA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="RA-1" selected="true"/>
            <select idref="RA-2" selected="true"/>
            <select idref="RA-3" selected="true"/>
            <select idref="RA-4" selected="true"/>
            <select idref="RA-5" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SA-1" selected="true"/>
            <select idref="SA-2" selected="true"/>
            <select idref="SA-3" selected="true"/>
            <select idref="SA-4" selected="true"/>
            <select idref="SA-5" selected="true"/>
            <select idref="SA-6" selected="true"/>
            <select idref="SA-7" selected="true"/>
            <select idref="SA-8" selected="false"/>
            <select idref="SA-9" selected="true"/>
            <select idref="SA-10" selected="false"/>
            <select idref="SA-11" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SC-1" selected="true"/>
            <select idref="SC-2" selected="true"/>
            <select idref="SC-3" selected="true"/>
            <select idref="SC-4" selected="true"/>
            <select idref="SC-5" selected="true"/>
            <select idref="SC-6" selected="true"/>
            <select idref="SC-7" selected="true"/>
            <select idref="SC-8" selected="true"/>
            <select idref="SC-9" selected="true"/>
            <select idref="SC-10" selected="true"/>
            <select idref="SC-11" selected="false"/>
            <select idref="SC-12" selected="true"/>
            <select idref="SC-13" selected="true"/>
            <select idref="SC-14" selected="true"/>
            <select idref="SC-15" selected="true"/>
            <select idref="SC-16" selected="false"/>
            <select idref="SC-17" selected="true"/>
            <select idref="SC-18" selected="true"/>
            <select idref="SC-19" selected="true"/>
            <select idref="SC-20" selected="true"/>
            <select idref="SC-21" selected="true"/>
            <select idref="SC-22" selected="true"/>
            <select idref="SC-23" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SI  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SI-1" selected="true"/>
            <select idref="SI-2" selected="true"/>
            <select idref="SI-3" selected="true"/>
            <select idref="SI-4" selected="true"/>
            <select idref="SI-5" selected="true"/>
            <select idref="SI-6" selected="true"/>
            <select idref="SI-7" selected="true"/>
            <select idref="SI-8" selected="true"/>
            <select idref="SI-9" selected="true"/>
            <select idref="SI-10" selected="true"/>
            <select idref="SI-11" selected="true"/>
            <select idref="SI-12" selected="true"/>
      </Profile>
      <Profile id="all_800_53" abstract="true">
            <title>800-53 All</title>
            <description>This profile selects all the security controls that are recommended by Special Publication 800-53 for information systems. Each control has an effect on other groups within this document as individual rule require certain controls to be selected.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AC-1" selected="true"/>
            <select idref="AC-2" selected="true"/>
            <select idref="AC-3" selected="true"/>
            <select idref="AC-4" selected="true"/>
            <select idref="AC-5" selected="true"/>
            <select idref="AC-6" selected="true"/>
            <select idref="AC-7" selected="true"/>
            <select idref="AC-8" selected="true"/>
            <select idref="AC-9" selected="true"/>
            <select idref="AC-10" selected="true"/>
            <select idref="AC-11" selected="true"/>
            <select idref="AC-12" selected="true"/>
            <select idref="AC-13" selected="true"/>
            <select idref="AC-14" selected="true"/>
            <select idref="AC-15" selected="true"/>
            <select idref="AC-16" selected="true"/>
            <select idref="AC-17" selected="true"/>
            <select idref="AC-18" selected="true"/>
            <select idref="AC-19" selected="true"/>
            <select idref="AC-20" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AT  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AT-1" selected="true"/>
            <select idref="AT-2" selected="true"/>
            <select idref="AT-3" selected="true"/>
            <select idref="AT-4" selected="true"/>
            <select idref="AT-5" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AU  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AU-1" selected="true"/>
            <select idref="AU-2" selected="true"/>
            <select idref="AU-3" selected="true"/>
            <select idref="AU-4" selected="true"/>
            <select idref="AU-5" selected="true"/>
            <select idref="AU-6" selected="true"/>
            <select idref="AU-7" selected="true"/>
            <select idref="AU-8" selected="true"/>
            <select idref="AU-9" selected="true"/>
            <select idref="AU-10" selected="true"/>
            <select idref="AU-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CA-1" selected="true"/>
            <select idref="CA-2" selected="true"/>
            <select idref="CA-3" selected="true"/>
            <select idref="CA-4" selected="true"/>
            <select idref="CA-5" selected="true"/>
            <select idref="CA-6" selected="true"/>
            <select idref="CA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CM  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CM-1" selected="true"/>
            <select idref="CM-2" selected="true"/>
            <select idref="CM-3" selected="true"/>
            <select idref="CM-4" selected="true"/>
            <select idref="CM-5" selected="true"/>
            <select idref="CM-6" selected="true"/>
            <select idref="CM-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CP-1" selected="true"/>
            <select idref="CP-2" selected="true"/>
            <select idref="CP-3" selected="true"/>
            <select idref="CP-4" selected="true"/>
            <select idref="CP-5" selected="true"/>
            <select idref="CP-6" selected="true"/>
            <select idref="CP-7" selected="true"/>
            <select idref="CP-8" selected="true"/>
            <select idref="CP-9" selected="true"/>
            <select idref="CP-10" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IA-1" selected="true"/>
            <select idref="IA-2" selected="true"/>
            <select idref="IA-3" selected="true"/>
            <select idref="IA-4" selected="true"/>
            <select idref="IA-5" selected="true"/>
            <select idref="IA-6" selected="true"/>
            <select idref="IA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IR  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IR-1" selected="true"/>
            <select idref="IR-2" selected="true"/>
            <select idref="IR-3" selected="true"/>
            <select idref="IR-4" selected="true"/>
            <select idref="IR-5" selected="true"/>
            <select idref="IR-6" selected="true"/>
            <select idref="IR-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MA-1" selected="true"/>
            <select idref="MA-2" selected="true"/>
            <select idref="MA-3" selected="true"/>
            <select idref="MA-4" selected="true"/>
            <select idref="MA-5" selected="true"/>
            <select idref="MA-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MP-1" selected="true"/>
            <select idref="MP-2" selected="true"/>
            <select idref="MP-3" selected="true"/>
            <select idref="MP-4" selected="true"/>
            <select idref="MP-5" selected="true"/>
            <select idref="MP-6" selected="true"/>
            <select idref="MP-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PE  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PE-1" selected="true"/>
            <select idref="PE-2" selected="true"/>
            <select idref="PE-3" selected="true"/>
            <select idref="PE-4" selected="true"/>
            <select idref="PE-5" selected="true"/>
            <select idref="PE-6" selected="true"/>
            <select idref="PE-7" selected="true"/>
            <select idref="PE-8" selected="true"/>
            <select idref="PE-9" selected="true"/>
            <select idref="PE-10" selected="true"/>
            <select idref="PE-11" selected="true"/>
            <select idref="PE-12" selected="true"/>
            <select idref="PE-13" selected="true"/>
            <select idref="PE-14" selected="true"/>
            <select idref="PE-15" selected="true"/>
            <select idref="PE-16" selected="true"/>
            <select idref="PE-17" selected="true"/>
            <select idref="PE-18" selected="true"/>
            <select idref="PE-19" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PL  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PL-1" selected="true"/>
            <select idref="PL-2" selected="true"/>
            <select idref="PL-3" selected="true"/>
            <select idref="PL-4" selected="true"/>
            <select idref="PL-5" selected="true"/>
            <select idref="PL-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PS  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PS-1" selected="true"/>
            <select idref="PS-2" selected="true"/>
            <select idref="PS-3" selected="true"/>
            <select idref="PS-4" selected="true"/>
            <select idref="PS-5" selected="true"/>
            <select idref="PS-6" selected="true"/>
            <select idref="PS-7" selected="true"/>
            <select idref="PS-8" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  RA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="RA-1" selected="true"/>
            <select idref="RA-2" selected="true"/>
            <select idref="RA-3" selected="true"/>
            <select idref="RA-4" selected="true"/>
            <select idref="RA-5" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SA-1" selected="true"/>
            <select idref="SA-2" selected="true"/>
            <select idref="SA-3" selected="true"/>
            <select idref="SA-4" selected="true"/>
            <select idref="SA-5" selected="true"/>
            <select idref="SA-6" selected="true"/>
            <select idref="SA-7" selected="true"/>
            <select idref="SA-8" selected="true"/>
            <select idref="SA-9" selected="true"/>
            <select idref="SA-10" selected="true"/>
            <select idref="SA-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SC-1" selected="true"/>
            <select idref="SC-2" selected="true"/>
            <select idref="SC-3" selected="true"/>
            <select idref="SC-4" selected="true"/>
            <select idref="SC-5" selected="true"/>
            <select idref="SC-6" selected="true"/>
            <select idref="SC-7" selected="true"/>
            <select idref="SC-8" selected="true"/>
            <select idref="SC-9" selected="true"/>
            <select idref="SC-10" selected="true"/>
            <select idref="SC-11" selected="true"/>
            <select idref="SC-12" selected="true"/>
            <select idref="SC-13" selected="true"/>
            <select idref="SC-14" selected="true"/>
            <select idref="SC-15" selected="true"/>
            <select idref="SC-16" selected="true"/>
            <select idref="SC-17" selected="true"/>
            <select idref="SC-18" selected="true"/>
            <select idref="SC-19" selected="true"/>
            <select idref="SC-20" selected="true"/>
            <select idref="SC-21" selected="true"/>
            <select idref="SC-22" selected="true"/>
            <select idref="SC-23" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SI  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SI-1" selected="true"/>
            <select idref="SI-2" selected="true"/>
            <select idref="SI-3" selected="true"/>
            <select idref="SI-4" selected="true"/>
            <select idref="SI-5" selected="true"/>
            <select idref="SI-6" selected="true"/>
            <select idref="SI-7" selected="true"/>
            <select idref="SI-8" selected="true"/>
            <select idref="SI-9" selected="true"/>
            <select idref="SI-10" selected="true"/>
            <select idref="SI-11" selected="true"/>
            <select idref="SI-12" selected="true"/>
      </Profile>
      <!-- ==================================================================================================== -->
      <!-- =========================================  FDCC PROFILES  ========================================== -->
      <!-- ==================================================================================================== -->
      <!--                                                                                                      -->
      <!-- These profiles outline the specific guidance outlined by the Federal Desktop Core Configuration.     -->
      <!-- Each defines the set of XCCDF rules that are applicable for that guidance as well as specific values -->
      <!-- to be used when determining complinace.                                                              -->
      <!--                                                                                                      -->
      <Profile id="federal_desktop_core_configuration_version_1.2.0.0" extends="all_800_53">
            <title>Federal Desktop Core Configuration version 1.2.0.0</title>
            <description>This profile represents guidance outlined by the Federal Core Configuration for a desktop system with Microsoft Internet Explorer 7 installed.</description>
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- '''  3 - FDCC Other Settings                                                               ''' -->
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- Core Policy -->
            <select idref="DisableConfiguringHistory_LocalComputer" selected="true"/>
            <select idref="DisableAutomaticInstallOfIEComponents_LocalComputer" selected="true"/>
            <select idref="DisableChangingAutomaticConfigurationSettings_LocalComputer" selected="true"/>
            <select idref="DisablePeriodicCheckForIESoftwareUpdates_LocalComputer" selected="true"/>
            <select idref="DisableShowingSplashScreen_LocalComputer" selected="true"/>
            <select idref="DisableSoftwareUpdateShellNotifications_LocalComputer" selected="true"/>
            <select idref="DoNotAllowUsersEnableDisableAddOns_LocalComputer" selected="true"/>
            <select idref="MakeProxySettingsPerMachine_LocalComputer" selected="true"/>
            <select idref="PreventParticipationInCustomerExperienceImprovementPrograms_LocalComputer" selected="true"/>
            <select idref="PreventPerformanceOfFirstRunCustomizeSettings_LocalComputer" selected="true"/>
            <select idref="DoNotAllowUsersAddDeleteSites_LocalComputer" selected="true"/>
            <select idref="DoNotAllowUsersChangePolicies_LocalComputer" selected="true"/>
            <select idref="use_only_machine_settings_local_computer" selected="true"/>
            <select idref="TurnOffCrashDetection_LocalComputer" selected="true"/>
            <select idref="TurnOffManagingPhishingFilter_LocalComputer" selected="true"/>
            <select idref="TurnOffSecuritySettingsCheckFeature_LocalComputer" selected="true"/>
            <!-- Internet Control Panel Policy -->
            <!-- Advanced Page Policy -->
            <select idref="AllowActiveContentFromCD_LocalComputer" selected="true"/>
            <select idref="AllowSoftwareRunInstallSignatureInvalid_LocalComputer" selected="true"/>
            <select idref="AllowThird-PartyBrowserExtensions_LocalComputer" selected="true"/>
            <select idref="AutomaticallyCheckIEUpdates_LocalComputer" selected="true"/>
            <select idref="CheckServerCertificateRevocation_LocalComputer" selected="true"/>
            <select idref="CheckSignatureDownloadedPrograms_LocalComputer" selected="true"/>
            <!-- Security Page Policy -->
            <select idref="include_all_network_paths_local_computer" selected="true"/>
            <select idref="site_to_zone_assignment_list_local_computer" selected="true"/>
            <!-- InternetZone_LocalComputer -->
            <select idref="access_data_sources_across_domains_internet_zone_local_computer" selected="true"/>
            <select idref="allow_cut_copy_paste_operations_from_clipboard_via_script_internet_zone_local_computer" selected="true"/>
            <select idref="AllowDragDropOrCopyPasteFiles_InternetZone_LocalComputer" selected="true"/>
            <select idref="AllowFontDownloads_InternetZone_LocalComputer" selected="true"/>
            <select idref="AllowInstallationOfDesktopItems_InternetZone_LocalComputer" selected="true"/>
            <select idref="AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_InternetZone_LocalComputer" selected="true"/>
            <select idref="allow_scriptlets_internet_zone_local_computer" selected="true"/>
            <select idref="AutomaticPromptingFileDownloads_InternetZone_LocalComputer" selected="true"/>
            <select idref="DownloadUnsignedActiveXControls_InternetZone_LocalComputer" selected="true"/>
            <select idref="InitializeScriptActiveXControlsNotMarkedAsSafe_InternetZone_LocalComputer" selected="true"/>
            <select idref="java_permissions_internet_zone_local_computer" selected="true"/>
            <select idref="LaunchingApplicationsAndFilesInIFRAME_InternetZone_LocalComputer" selected="true"/>
            <select idref="LogonOptions_InternetZone_LocalComputer" selected="true"/>
            <select idref="LooseXAMLFiles_InternetZone_LocalComputer" selected="true"/>
            <select idref="navigate_sub_frames_across_different_domains_Internet_zone_local_computer" selected="true"/>
            <select idref="OpenFilesBasedOnContent_InternetZone_LocalComputer" selected="true"/>
            <select idref="SoftwareChannelPermissions_InternetZone_LocalComputer" selected="true"/>
            <select idref="TurnOffFirstRunOptIn_InternetZone_LocalComputer" selected="true"/>
            <select idref="TurnOnProtectedMode_InternetZone_LocalComputer" selected="true"/>
            <select idref="UsePop-upBlocker_InternetZone_LocalComputer" selected="true"/>
            <select idref="UserdataPersistence_InternetZone_LocalComputer" selected="true"/>
            <select idref="WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_InternetZone_LocalComputer" selected="true"/>
            <!-- intranet_zone_local_computer-->
            <select idref="java_permissions_intranet_zone_local_computer" selected="true"/>
            <select idref="java_permissions_local_machine_zone_local_computer" selected="true"/>
            <!-- local_machine_zone_local_computer-->
            <!-- locked_down_internet_zone_local_computer -->
            <select idref="java_permissions_locked_down_internet_zone_local_computer" selected="true"/>
            <!-- LockedDownintranet_zone_local_computer -->
            <select idref="java_permissions_LockedDownintranet_zone_local_computer" selected="true"/>
            <!-- LockedDownlocal_machine_zone_local_computer -->
            <select idref="java_permissions_LockedDownlocal_machine_zone_local_computer" selected="true"/>
            <!-- LockedDownRestrictedSitesZone_LocalComputer -->
            <select idref="java_permissions_LockedDownRestrictedSitesZone_LocalComputer" selected="true"/>
            <!-- LockedDowntrusted_sites_zone_local_computer-->
            <select idref="java_permissions_LockedDowntrusted_sites_zone_local_computer" selected="true"/>
            <!-- RestrictedSitesZone_LocalComputer -->
            <select idref="AccessDataSourcesAcrossDomains_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="AllowActiveScripting_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="AllowBinaryAndScriptBehaviors_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="AllowCutCopyPasteOperationsFromClipboardViaScript_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="AllowDragDropOrCopyPasteFiles_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="AllowFileDownloads_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="AllowFontDownloads_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="AllowInstallationOfDesktopItems_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="AllowMETAREFRESH_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="AutomaticPromptingFileDownloads_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="DownloadUnsignedActiveXControls_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="InitializeScriptActiveXControlsNotMarkedAsSafe_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="java_permissions_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="LaunchingApplicationsAndFilesInIFRAME_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="LogonOptions_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="LooseXAMLFiles_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="NavigateSub-framesAcrossDifferentDomains_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="OpenFilesBasedOnContent_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="RunNETFrameworkReliantComponentsNotSignedWithAuthenticode_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="RunNETFrameworkReliantComponentsSignedWithAuthenticode_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="RunActiveXControlsAndPlugins_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="ScriptActiveXControlsMarkedSafeForScripting_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="ScriptingOfJavaApplets_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="SoftwareChannelPermissions_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="TurnOffFirstRunOptIn_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="TurnOnProtectedMode_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="UsePop-upBlocker_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="UserdataPersistence_RestrictedSitesZone_LocalComputer" selected="true"/>
            <select idref="WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_RestrictedSitesZone_LocalComputer" selected="true"/>
            <!-- trusted_sites_zone_local_computer -->
            <select idref="java_permissions_trusted_sites_zone_local_computer" selected="true"/>
            <!-- Periodic Check For Updates Policy -->
            <select idref="TurnOffChangingURLDisplay_LocalComputer" selected="true"/>
            <select idref="TurnOffConfiguringUpdateCheckInterval_LocalComputer" selected="true"/>
            <!-- Security Page Policy -->
            <select idref="IEProcesses_ConsistentMimeHandling_LocalComputer" selected="true"/>
            <select idref="IEProcesses_MimeSniffingSafetyFeature_LocalComputer" selected="true"/>
            <select idref="IEProcesses_MKProtocolSecurityRestriction_LocalComputer" selected="true"/>
            <select idref="IEProcesses_ProtectionFromZoneElevation_LocalComputer" selected="true"/>
            <select idref="IEProcesses_RestrictFileDownload_LocalComputer" selected="true"/>
            <select idref="IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer" selected="true"/>
            <!-- Local User Policy -->
            <select idref="configure_outlook_express_local_user" selected="true"/>
            <select idref="DisableAutoCompleteForForms_LocalUser" selected="true"/>
            <select idref="DisableExternalBrandingOfIE_LocalUser" selected="true"/>
            <select idref="TurnOnAutoCompleteFeatureForUserNamesAndPasswords_LocalUser" selected="true"/>
            <select idref="TurnOffPageTransitions_LocalUser" selected="true"/>
            <select idref="TurnOnInternetConnectionWizardAutoDetect_LocalUser" selected="true"/>
            <select idref="Turn_off_downloading_enclosures" selected="true"/>
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- '''  4 - Fully Patched System                                                              ''' -->
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <select idref="security_patches_up_to_date" selected="true"/>
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <refine-value idref="DisableConfiguringHistory_LocalComputer_1_var" selector="enabled"/>
            <refine-value idref="DisableConfiguringHistory_LocalComputer_2_var" selector="40_days"/>
            <refine-value idref="DisableAutomaticInstallOfIEComponents_LocalComputer_var" selector="enabled"/>
            <refine-value idref="DisableChangingAutomaticConfigurationSettings_LocalComputer_var" selector="enabled"/>
            <refine-value idref="DisablePeriodicCheckForIESoftwareUpdates_LocalComputer_var" selector="enabled"/>
            <refine-value idref="DisableShowingSplashScreen_LocalComputer_var" selector="enabled"/>
            <refine-value idref="DisableSoftwareUpdateShellNotifications_LocalComputer_var" selector="enabled"/>
            <refine-value idref="DoNotAllowUsersEnableDisableAddOns_LocalComputer_var" selector="disabled"/>
            <refine-value idref="MakeProxySettingsPerMachine_LocalComputer_var" selector="disabled"/>
            <refine-value idref="PreventParticipationInCustomerExperienceImprovementPrograms_LocalComputer_var" selector="enabled"/>
            <refine-value idref="PreventPerformanceOfFirstRunCustomizeSettings_LocalComputer_var" selector="enabled:home_page"/>
            <refine-value idref="DoNotAllowUsersAddDeleteSites_LocalComputer_var" selector="enabled"/>
            <refine-value idref="DoNotAllowUsersChangePolicies_LocalComputer_var" selector="enabled"/>
            <refine-value idref="use_only_machine_settings_local_computer_var" selector="enabled"/>
            <refine-value idref="TurnOffCrashDetection_LocalComputer_var" selector="enabled"/>
            <refine-value idref="TurnOffManagingPhishingFilter_LocalComputer_var" selector="enabled:off"/>
            <refine-value idref="TurnOffSecuritySettingsCheckFeature_LocalComputer_var" selector="disabled"/>
            <refine-value idref="AllowActiveContentFromCD_LocalComputer_var" selector="disabled"/>
            <refine-value idref="AllowSoftwareRunInstallSignatureInvalid_LocalComputer_var" selector="disabled"/>
            <refine-value idref="AllowThird-PartyBrowserExtensions_LocalComputer_var" selector="disabled"/>
            <refine-value idref="AutomaticallyCheckIEUpdates_LocalComputer_var" selector="disabled"/>
            <refine-value idref="CheckServerCertificateRevocation_LocalComputer_var" selector="enabled"/>
            <refine-value idref="CheckSignatureDownloadedPrograms_LocalComputer_var" selector="enabled"/>
            <refine-value idref="include_all_network_paths_local_computer_var" selector="disabled"/>
            <refine-value idref="access_data_sources_across_domains_internet_zone_local_computer_var" selector="enabled:disable"/>
            <refine-value idref="allow_cut_copy_paste_operations_from_clipboard_via_script_internet_zone_local_computer_var" selector="enabled:disable"/>
            <refine-value idref="AllowDragDropOrCopyPasteFiles_InternetZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="AllowFontDownloads_InternetZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="AllowInstallationOfDesktopItems_InternetZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_InternetZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="allow_scriptlets_internet_zone_local_computer_var" selector="enabled:disable"/>
            <refine-value idref="AutomaticPromptingFileDownloads_InternetZone_LocalComputer_var" selector="enabled:enable"/>
            <refine-value idref="DownloadUnsignedActiveXControls_InternetZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="InitializeScriptActiveXControlsNotMarkedAsSafe_InternetZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="java_permissions_internet_zone_local_computer_var" selector="enabled:disable-java"/>
            <refine-value idref="LaunchingApplicationsAndFilesInIFRAME_InternetZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="LogonOptions_InternetZone_LocalComputer_var" selector="enabled:prompt_for_user_name_and_password"/>
            <refine-value idref="LooseXAMLFiles_InternetZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="navigate_sub_frames_across_different_domains_Internet_zone_local_computer_var" selector="FDCC"/>
            <refine-value idref="OpenFilesBasedOnContent_InternetZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="SoftwareChannelPermissions_InternetZone_LocalComputer_var" selector="enabled:high_safety"/>
            <refine-value idref="TurnOffFirstRunOptIn_InternetZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="TurnOnProtectedMode_InternetZone_LocalComputer_var" selector="enabled:enable"/>
            <refine-value idref="UsePop-upBlocker_InternetZone_LocalComputer_var" selector="enabled:enable"/>
            <refine-value idref="UserdataPersistence_InternetZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_InternetZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="java_permissions_intranet_zone_local_computer_var" selector="enabled:high-safety"/>
            <refine-value idref="java_permissions_local_machine_zone_local_computer_var" selector="enabled:disable-java"/>
            <refine-value idref="java_permissions_locked_down_internet_zone_local_computer_var" selector="enabled:disable-java"/>
            <refine-value idref="java_permissions_LockedDownintranet_zone_local_computer_var" selector="enabled:disable-java"/>
            <refine-value idref="java_permissions_LockedDownlocal_machine_zone_local_computer_var" selector="enabled:disable-java"/>
            <refine-value idref="java_permissions_LockedDownRestrictedSitesZone_LocalComputer_var" selector="enabled:disable-java"/>
            <refine-value idref="java_permissions_LockedDowntrusted_sites_zone_local_computer_var" selector="enabled:disable-java"/>
            <refine-value idref="AccessDataSourcesAcrossDomains_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="AllowActiveScripting_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="AllowBinaryAndScriptBehaviors_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="AllowCutCopyPasteOperationsFromClipboardViaScript_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="AllowDragDropOrCopyPasteFiles_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="AllowFileDownloads_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="AllowFontDownloads_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="AllowInstallationOfDesktopItems_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="AllowMETAREFRESH_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="AutomaticPromptingFileDownloads_RestrictedSitesZone_LocalComputer_var" selector="enabled:enable"/>
            <refine-value idref="DownloadUnsignedActiveXControls_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="InitializeScriptActiveXControlsNotMarkedAsSafe_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="java_permissions_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable-java"/>
            <refine-value idref="LaunchingApplicationsAndFilesInIFRAME_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="LogonOptions_RestrictedSitesZone_LocalComputer_var" selector="enabled:anonymous_logon"/>
            <refine-value idref="LooseXAMLFiles_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="NavigateSub-framesAcrossDifferentDomains_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="OpenFilesBasedOnContent_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="RunNETFrameworkReliantComponentsNotSignedWithAuthenticode_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="RunNETFrameworkReliantComponentsSignedWithAuthenticode_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="RunActiveXControlsAndPlugins_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="ScriptActiveXControlsMarkedSafeForScripting_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="ScriptingOfJavaApplets_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="SoftwareChannelPermissions_RestrictedSitesZone_LocalComputer_var" selector="enabled:high_safety"/>
            <refine-value idref="TurnOffFirstRunOptIn_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="TurnOnProtectedMode_RestrictedSitesZone_LocalComputer_var" selector="enabled:enable"/>
            <refine-value idref="UsePop-upBlocker_RestrictedSitesZone_LocalComputer_var" selector="enabled:enable"/>
            <refine-value idref="UserdataPersistence_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_RestrictedSitesZone_LocalComputer_var" selector="enabled:disable"/>
            <refine-value idref="java_permissions_trusted_sites_zone_local_computer_var" selector="enabled:high-safety"/>
            <refine-value idref="TurnOffConfiguringUpdateCheckInterval_LocalComputer_var" selector="30_days"/>
            <refine-value idref="IEProcesses_ConsistentMimeHandling_LocalComputer_1_var" selector="enabled"/>
            <refine-value idref="IEProcesses_ConsistentMimeHandling_LocalComputer_2_var" selector="enabled"/>
            <refine-value idref="IEProcesses_ConsistentMimeHandling_LocalComputer_3_var" selector="enabled"/>
            <refine-value idref="IEProcesses_MimeSniffingSafetyFeature_LocalComputer_1_var" selector="enabled"/>
            <refine-value idref="IEProcesses_MimeSniffingSafetyFeature_LocalComputer_2_var" selector="enabled"/>
            <refine-value idref="IEProcesses_MimeSniffingSafetyFeature_LocalComputer_3_var" selector="enabled"/>
            <refine-value idref="IEProcesses_MKProtocolSecurityRestriction_LocalComputer_1_var" selector="enabled"/>
            <refine-value idref="IEProcesses_MKProtocolSecurityRestriction_LocalComputer_2_var" selector="enabled"/>
            <refine-value idref="IEProcesses_MKProtocolSecurityRestriction_LocalComputer_3_var" selector="enabled"/>
            <refine-value idref="IEProcesses_ProtectionFromZoneElevation_LocalComputer_1_var" selector="enabled"/>
            <refine-value idref="IEProcesses_ProtectionFromZoneElevation_LocalComputer_2_var" selector="enabled"/>
            <refine-value idref="IEProcesses_ProtectionFromZoneElevation_LocalComputer_3_var" selector="enabled"/>
            <refine-value idref="IEProcesses_RestrictFileDownload_LocalComputer_1_var" selector="enabled"/>
            <refine-value idref="IEProcesses_RestrictFileDownload_LocalComputer_2_var" selector="enabled"/>
            <refine-value idref="IEProcesses_RestrictFileDownload_LocalComputer_3_var" selector="enabled"/>
            <refine-value idref="IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer_1_var" selector="enabled"/>
            <refine-value idref="IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer_2_var" selector="enabled"/>
            <refine-value idref="IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer_3_var" selector="enabled"/>
            <refine-value idref="configure_outlook_express_local_user_var" selector="disabled"/>
            <refine-value idref="DisableAutoCompleteForForms_LocalUser_1_var" selector="enabled"/>
            <refine-value idref="DisableAutoCompleteForForms_LocalUser_2_var" selector="enabled"/>
            <refine-value idref="DisableExternalBrandingOfIE_LocalUser_var" selector="enabled"/>
            <refine-value idref="TurnOnAutoCompleteFeatureForUserNamesAndPasswords_LocalUser_1_var" selector="disabled"/>
            <refine-value idref="TurnOnAutoCompleteFeatureForUserNamesAndPasswords_LocalUser_2_var" selector="disabled"/>
            <refine-value idref="TurnOffPageTransitions_LocalUser_var" selector="enabled"/>
            <refine-value idref="TurnOnInternetConnectionWizardAutoDetect_LocalUser_var" selector="disabled"/>
            <refine-value idref="Turn_off_downloading_enclosures_var" selector="enabled"/>
      </Profile>
      <!-- ==================================================================================================== -->
      <!-- ================================  NIST SP 800-53 (FISMA) Controls  ================================= -->
      <!-- ==================================================================================================== -->
      <!--                                                                                                      -->
      <!-- The following group contains all the different controls defined by NIST SP 800-53.  These controls   -->
      <!-- are hidden as they should not appear in any document generated from this file pertaining to specific -->
      <!-- security guidance.  These controls are used by the 800-53 profiles to enable high-level guidance     -->
      <!-- that is then passed down to the FDCC profiles and used to enable specific XCCDF Rules.               -->
      <!--                                                                                                      -->
      <Group id="nist_sp80053_controls" hidden="true">
            <title>NIST SP 800-53 Controls</title>
            <Group id="access_control_checks" hidden="true">
                  <title>Applicable 800-53 Access Control Checks</title>
                  <Group id="AC-1" hidden="true">
                        <title>Access Control Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 11.1.1, 11.4.1, 15.1.1</reference>
                        <reference>NIST 800-26: 15, 16</reference>
                        <reference>DOD 8500.2: ECAN-1, ECPA-1, PRAS-1, DCAR-1</reference>
                        <reference>DCID 6/3: 2.B.4.e(5), 4.B.1.a(1)(b)</reference>
                  </Group>
                  <Group id="AC-2" hidden="true">
                        <title>Account Management</title>
                        <reference>ISO/IEC 17799: 6.2.2, 6.2.3, 8.3.3, 11.2.1, 11.2.2, 11.2.4, 11.7.2</reference>
                        <reference>NIST 800-26: 6.1.8, 15.1.1, 15.1.4, 15.1.15, 15.1.8, 15.2.2, 16.1.3, 16.1.5, 16.2.12</reference>
                        <reference>GAO FISCAM: AC-2.1 AC-2.2, AC-3.2, SP-4.1</reference>
                        <reference>DOD 8500.2: IAAC-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(3)</reference>
                  </Group>
                  <Group id="AC-3" hidden="true">
                        <title>Access Enforcement</title>
                        <reference>ISO/IEC 17799: 11.2.4, 11.4.5</reference>
                        <reference>NIST 800-26: 10.1.2, 15.1.1, 16.1.1, 16.1.2, 16.1.3, 16.1.7, 16.1.9, 16.2.1, 16.2.7, 16.2.10, 16.2.11, 16.2.15</reference>
                        <reference>GAO FISCAM: AC-2, AC-3.2</reference>
                        <reference>DOD 8500.2: DCFA-1, ECAN-1, EBRU-1, PRNK-1, ECCD-1, ECSD-2</reference>
                        <reference>DCID 6/3: Discretionary Access Control (DAC): 4.B.2.a(2), Mandatory Access Control (MAC): 4.B.4.a(3)</reference>
                  </Group>
                  <Group id="AC-4" hidden="true">
                        <title>Information Flow Enforcement</title>
                        <reference>ISO/IEC 17799: 10.6.2, 11.4.5, 11.4.6, 11.4.7</reference>
                        <reference>DOD 8500.2: EBBD-1, EBBD-2</reference>
                        <reference>DCID 6/3: 4.B.3.a(3), 7.B.3.g</reference>
                  </Group>
                  <Group id="AC-5" hidden="true">
                        <title>Separation of Duties</title>
                        <reference>ISO/IEC 17799: 10.1.3, 10.6.1, 10.10.1</reference>
                        <reference>NIST 800-26: 6.1.1, 6.1.2, 6.1.3, 15.2.1, 16.1.2, 17.1.5</reference>
                        <reference>GAO FISCAM: AC-3.2, SD-1.2</reference>
                        <reference>DOD 8500.2: ECLP-1</reference>
                        <reference>DCID 6/3: 2.A.1, 4.B.3.a(18)</reference>
                  </Group>
                  <Group id="AC-6" hidden="true">
                        <title>Least Privilege</title>
                        <reference>ISO/IEC 17799: 11.2.2</reference>
                        <reference>NIST 800-26: 16.1.2, 16.1.3, 17.1.5</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECLP-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(10)</reference>
                  </Group>
                  <Group id="AC-7" hidden="true">
                        <title>Unsuccessful Login Attempts</title>
                        <reference>ISO/IEC 17799: 11.5.1</reference>
                        <reference>NIST 800-26: 15.1.14</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECLO-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(17)(c)-(d)</reference>
                  </Group>
                  <Group id="AC-8" hidden="true">
                        <title>System Use Notification</title>
                        <reference>ISO/IEC 17799: 11.5.1, 15.1.5</reference>
                        <reference>NIST 800-26: 16.2.13, 16.3.1, 17.1.9</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECWM-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(6)</reference>
                  </Group>
                  <Group id="AC-9" hidden="true">
                        <title>Previous Logon Notification</title>
                        <reference>ISO/IEC 17799: 11.5.1</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECLO-2</reference>
                  </Group>
                  <Group id="AC-10" hidden="true">
                        <title>Concurrent Session Control</title>
                        <reference>DOD 8500.2: ECLO-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(17)(a)</reference>
                  </Group>
                  <Group id="AC-11" hidden="true">
                        <title>Session Lock</title>
                        <reference>ISO/IEC 17799: 11.3.2</reference>
                        <reference>NIST 800-26: 16.1.4</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: PESL-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(5)</reference>
                  </Group>
                  <Group id="AC-12" hidden="true">
                        <title>Session Termination</title>
                        <reference>ISO/IEC 17799: 11.3.2, 11.5.5</reference>
                        <reference>NIST 800-26: 16.1.4, 16.2.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DCID 6/3: 4.B.2.a(17)(b)</reference>
                  </Group>
                  <Group id="AC-13" hidden="true">
                        <title>Supervision and Review—Access Control</title>
                        <reference>ISO/IEC 17799: 10.10.2, 11.2.4</reference>
                        <reference>NIST 800-26: 7.1.10, 11.2.2, 16.1.10, 16.2.5, 17.1.6, 17.1.7</reference>
                        <reference>GAO FISCAM: AC-4, AC-4.3, SS-2.2</reference>
                        <reference>DOD 8500.2: ECAT-1, ECAT-2, E3.3.9</reference>
                        <reference>DCID 6/3: 2.B.7.c, 4.B.3.a(8)(b)</reference>
                  </Group>
                  <Group id="AC-14" hidden="true">
                        <title>Permitted Actions without Identification or Authentication</title>
                        <reference>NIST 800-26: 16.2.12</reference>
                        <reference>DCID 6/3: 7.D.3.a</reference>
                  </Group>
                  <Group id="AC-15" hidden="true">
                        <title>Automated Marking</title>
                        <reference>ISO/IEC 17799: 7.2.2</reference>
                        <reference>NIST 800-26: 8.2.4, 16.1.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECML-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(11)</reference>
                  </Group>
                  <Group id="AC-16" hidden="true">
                        <title>Automated Labeling</title>
                        <reference>ISO/IEC 17799: 7.2.2</reference>
                        <reference>NIST 800-26: 16.1.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECML-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(3), 4.B.4.a(15), 4.B.4.a(16)</reference>
                  </Group>
                  <Group id="AC-17" hidden="true">
                        <title>Remote Access</title>
                        <reference>ISO/IEC 17799: 11.4.2, 11.4.3, 11.4.4</reference>
                        <reference>NIST 800-26: 16.2.4, 16.2.8</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: EBRP-1, EBRU-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(1)(b), 4.B.3.a(11), 7.D.2.e</reference>
                  </Group>
                  <Group id="AC-18" hidden="true">
                        <title>Wireless Access Restrictions</title>
                        <reference>ISO/IEC 17799: 11.4.2, 11.7.1, 11.7.2</reference>
                        <reference>DOD 8500.2: ECCT-1, ECWN-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(8), 5.B.3.a(11)</reference>
                  </Group>
                  <Group id="AC-19" hidden="true">
                        <title>Access Control for Portable and Mobile Systems</title>
                        <reference>ISO/IEC 17799: 11.7.1</reference>
                        <reference>NIST 800-26: 7.3.1, 7.3.2</reference>
                        <reference>DOD 8500.2: ECWN-1</reference>
                        <reference>DCID 6/3: 8.B.6.c, 9.G.4</reference>
                  </Group>
                  <Group id="AC-20" hidden="true">
                        <title>Use of External Information Systems</title>
                        <reference>ISO/IEC 17799: 6.1.4, 9.2.5, 11.7.1</reference>
                        <reference>NIST 800-26: 10.2.13</reference>
                        <reference>DCID 6/3: 8.B.6.c</reference>
                  </Group>
            </Group>
            <Group id="awareness_and_training" hidden="true">
                  <title>Applicable 800-53 Awareness and Training</title>
                  <Group id="AT-1" hidden="true">
                        <title>Security Awareness and Training Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 5.1.1, 8.2.2, 15.1.1</reference>
                        <reference>NIST 800-26: 13</reference>
                        <reference>DOD 8500.2: PRTN-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.3.c, Manual: 2.B.2.b(8); 2.B.4.e(6)</reference>
                  </Group>
                  <Group id="AT-2" hidden="true">
                        <title>Security Awareness</title>
                        <reference>ISO/IEC 17799: 6.2.3, 8.2.2, 10.4.1, 11.7.1, 13.1.1, 14.1.4, 15.1.4</reference>
                        <reference>NIST 800-26: 13.1.4, 13.1.5</reference>
                        <reference>DOD 8500.2: PRTN-1</reference>
                        <reference>DCID 6/3: 8.B.1</reference>
                  </Group>
                  <Group id="AT-3" hidden="true">
                        <title>Security Training</title>
                        <reference>ISO/IEC 17799: 8.2.2, 10.3.2, 11.7.1, 13.1.1, 14.1.4</reference>
                        <reference>NIST 800-26: 13.1, 13.1.3, 13.1.5</reference>
                        <reference>DOD 8500.2: PRTN-1</reference>
                        <reference>DCID 6/3: 8.B.1</reference>
                  </Group>
                  <Group id="AT-4" hidden="true">
                        <title>Security Training Records</title>
                        <reference>NIST 800-26: 13.1.2</reference>
                        <reference>DCID 6/3: 8.B.1</reference>
                  </Group>
                  <Group id="AT-5" hidden="true">
                        <title>Contacts with Security Groups and Associations</title>
                        <reference>ISO/IEC 17799: 6.1.7</reference>
                  </Group>
            </Group>
            <Group id="audit_and_accountablility" hidden="true">
                  <title>Applicable 800-53 Audit and Accountability</title>
                  <Group id="AU-1" hidden="true">
                        <title>Audit and Accountability Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.1, 15.1.1</reference>
                        <reference>NIST 800-26: 17</reference>
                        <reference>DOD 8500.2: ECAT-1, ECTB-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.d, Manual: 2.B.4.e(5); 4.B.2.a(4)</reference>
                  </Group>
                  <Group id="AU-2" hidden="true">
                        <title>Auditable Events</title>
                        <reference>ISO/IEC 17799: 10.10.1</reference>
                        <reference>NIST 800-26: 17.1.1, 17.1.2, 17.1.4</reference>
                        <reference>DOD 8500.2: ECAR-3</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(d)</reference>
                  </Group>
                  <Group id="AU-3" hidden="true">
                        <title>Content of Audit Records</title>
                        <reference>ISO/IEC 17799: 10.10.1, 10.10.4</reference>
                        <reference>NIST 800-26: 17.1.1</reference>
                        <reference>DOD 8500.2: ECAR-1, ECAR-2, ECAR-3, ECLC-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(a), 4.B.2.a(5)(a)</reference>
                  </Group>
                  <Group id="AU-4" hidden="true">
                        <title>Audit Storage Capacity</title>
                        <reference>ISO/IEC 17799: 10.10.3</reference>
                        <reference>DCID 6/3: 5.B.2.a(5)(a)(1)</reference>
                  </Group>
                  <Group id="AU-5" hidden="true">
                        <title>Response to Audit Processing Failures</title>
                        <reference>ISO/IEC 17799: 10.10.3</reference>
                        <reference>DCID 6/3: 4.B.4.a(9)(d)</reference>
                  </Group>
                  <Group id="AU-6" hidden="true">
                        <title>Audit Monitoring, Analysis, and Reporting</title>
                        <reference>ISO/IEC 17799: 10.10.2, 10.10.4, 13.2.1</reference>
                        <reference>NIST 800-26: 16.2.5, 17.1.7, 17.1.8</reference>
                        <reference>GAO FISCAM: AC-4.3</reference>
                        <reference>DOD 8500.2: ECAT-1, E3.3.9</reference>
                        <reference>DCID 6/3: 4.B.4.a(10)</reference>
                  </Group>
                  <Group id="AU-7" hidden="true">
                        <title>Audit Reduction and Report Generation</title>
                        <reference>ISO/IEC 17799: 10.10.3</reference>
                        <reference>NIST 800-26: 17.1.2, 17.1.7</reference>
                        <reference>DOD 8500.2: ECRG-1</reference>
                        <reference>DCID 6/3: 4.B.3.a(6)</reference>
                  </Group>
                  <Group id="AU-8" hidden="true">
                        <title>Time Stamps</title>
                        <reference>ISO/IEC 17799: 10.10.6</reference>
                        <reference>DOD 8500.2: ECAR-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(a)</reference>
                  </Group>
                  <Group id="AU-9" hidden="true">
                        <title>Protection of Audit Information</title>
                        <reference>ISO/IEC 17799: 10.10.3, 15.1.3, 15.3.2</reference>
                        <reference>NIST 800-26: 17.1.3, 17.1.4</reference>
                        <reference>DOD 8500.2: ECTP-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(b)</reference>
                  </Group>
                  <Group id="AU-10" hidden="true">
                        <title>Non-repudiation</title>
                        <reference>ISO/IEC 17799: 10.8.2, 10.9.1, 12.3.1</reference>
                        <reference>NIST 800-26: 15.1.2, 17.1.1</reference>
                        <reference>DOD 8500.2: DCNR-1</reference>
                        <reference>DCID 6/3: 5.B.3.a(8)</reference>
                  </Group>
                  <Group id="AU-11" hidden="true">
                        <title>Audit Record Retention</title>
                        <reference>ISO/IEC 17799: 10.10.1, 15.1.3</reference>
                        <reference>NIST 800-26: 17.1.4</reference>
                        <reference>DOD 8500.2: ECRR-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(c)</reference>
                  </Group>
            </Group>
            <Group id="certification_accreditation_and_security_assessment" hidden="true">
                  <title>Applicable 800-53 Certification, Accreditation, and Security Assessment</title>
                  <Group id="CA-1" hidden="true">
                        <title>Certification, Accreditation, and Security Assessment Policies and Procedures</title>
                        <reference>ISO/IEC 17799: 6.1.4, 10.3.2, 15.1.1</reference>
                        <reference>NIST 800-26: 2, 4</reference>
                        <reference>DOD 8500.2: DCAR-1, DCII-1</reference>
                        <reference>DCID 6/3: DCID: B.3, Manual: 2.B.2.b(1)</reference>
                  </Group>
                  <Group id="CA-2" hidden="true">
                        <title>Security Assessments</title>
                        <reference>ISO/IEC 17799: 6.1.8, 15.2.1, 15.2.2</reference>
                        <reference>NIST 800-26: 2.1.1, 2.1.3, 2.1.4</reference>
                        <reference>GAO FISCAM: SP-5.1</reference>
                        <reference>DOD 8500.2: DCII-1, ECMT-1, PEPS-1, E3.3.10</reference>
                        <reference>DCID 6/3: DCID: B.2.b; B.3.a, Manual: 4.B.2.b(6); 5.B.1.b(1); 9.B.1; 9.B.4</reference>
                  </Group>
                  <Group id="CA-3" hidden="true">
                        <title>Information System Connections</title>
                        <reference>ISO/IEC 17799: 10.6.2, 10.9.1, 11.4.5, 11.4.6, 11.4.7</reference>
                        <reference>NIST 800-26: 1.1.1, 3.2.9, 4.1.8, 12.2.3</reference>
                        <reference>GAO FISCAM: CC-2.1</reference>
                        <reference>DOD 8500.2: DCID-1, EBCR-1 EBRU-1, EBPW-1, ECIC-1</reference>
                        <reference>DCID 6/3: 9.B.3, 9.D.3.c</reference>
                  </Group>
                  <Group id="CA-4" hidden="true">
                        <title>Security Certification</title>
                        <reference>ISO/IEC 17799: 10.3.2</reference>
                        <reference>NIST 800-26: 2.1.2, 3.2.3, 3.2.5, 3.2.6, 4.1.1, 4.1.6, 11.2.8. 12.2.5</reference>
                        <reference>GAO FISCAM: CC-2.1</reference>
                        <reference>DOD 8500.2: DCAR-1, 5.7.5</reference>
                        <reference>DCID 6/3: DCID: B.3, Manual: 4.B.3.b(8); 9.E.2.a(2); 9.E.2.a(3)</reference>
                  </Group>
                  <Group id="CA-5" hidden="true">
                        <title>Plan of Action and Milestones</title>
                        <reference>ISO/IEC 17799: 15.2.1</reference>
                        <reference>NIST 800-26: 1.1.5, 1.2.3, 2.2.1, 4.2.1</reference>
                        <reference>GAO FISCAM: SP-5.1 SP-5.2</reference>
                        <reference>DOD 8500.2: 5.7.5</reference>
                        <reference>DCID 6/3: 9.E.2.a(3)(a)</reference>
                  </Group>
                  <Group id="CA-6" hidden="true">
                        <title>Security Accreditation</title>
                        <reference>ISO/IEC 17799: 10.3.2</reference>
                        <reference>NIST 800-26: 3.2.7, 12.2.5</reference>
                        <reference>DOD 8500.2: 5.7.5</reference>
                        <reference>DCID 6/3: DCID: B.3, Manual: 9.D.3; 9.D.4</reference>
                  </Group>
                  <Group id="CA-7" hidden="true">
                        <title>Continuous Monitoring</title>
                        <reference>ISO/IEC 17799: 15.2.1, 15.2.2</reference>
                        <reference>NIST 800-26: 10.2.1</reference>
                        <reference>DOD 8500.2: DCCB-1, DCPR-1, E3.3.9</reference>
                        <reference>DCID 6/3: DCID: B.2.d; Manual: 2.B.4.e(7); 2.B.5.c(10); 5.B.2.b(2); 9.B.1; 9.D.7</reference>
                  </Group>
            </Group>
            <Group id="configuration_management" hidden="true">
                  <title>Applicable 800-53 Configuration Management</title>
                  <Group id="CM-1" hidden="true">
                        <title>Configuration Management Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 12.4.1, 12.5.1, 15.1.1</reference>
                        <reference>DOD 8500.2: DCCB-1, DCPR-1, DCAR-1, E3.3.8</reference>
                        <reference>DCID 6/3: DCID: B.2.a Manual: 2.B.4.e(5); 5.B.2.a(5)</reference>
                  </Group>
                  <Group id="CM-2" hidden="true">
                        <title>Baseline Configuration and System Component Inventory</title>
                        <reference>ISO/IEC 17799: 7.1.1, 15.1.2</reference>
                        <reference>NIST 800-26: 1.1.1, 3.1.9, 10.2.7, 10.2.9, 12.1.4</reference>
                        <reference>GAO FISCAM: CC-2.3, CC-3.1, SS-1.2</reference>
                        <reference>DOD 8500.2: DCHW-1, DCSW-1</reference>
                        <reference>DCID 6/3: 2.B.7.c(7), 4.B.1.c(3), 4.B.2.b(6)</reference>
                  </Group>
                  <Group id="CM-3" hidden="true">
                        <title>Configuration Change Control</title>
                        <reference>ISO/IEC 17799: 10.1.2, 10.2.3, 12.4.1, 12.5.1, 12.5.2, 12.5.3</reference>
                        <reference>NIST 800-26: 3.1.4, 10.2.2, 10.2.3, 10.2.8, 10.2.10, 10.2.11</reference>
                        <reference>GAO FISCAM: SS-3.2, CC-2.2</reference>
                        <reference>DOD 8500.2: DCPR-1</reference>
                        <reference>DCID 6/3: 2.B.7.c(7) 4.B.1.c(3), 4.B.2.b(6), 5.B.2.a(5)</reference>
                  </Group>
                  <Group id="CM-4" hidden="true">
                        <title>Monitoring Configuration Changes</title>
                        <reference>ISO/IEC 17799: 10.1.2</reference>
                        <reference>NIST 800-26: 10.2.1, 10.2.4</reference>
                        <reference>GAO FISCAM: SS-3.1, SS-3.2, CC-2.1</reference>
                        <reference>DOD 8500.2: DCPR-1, E3.3.8</reference>
                        <reference>DCID 6/3: 2.B.7.c(7), 4.B.1.c(3), 5.B.2.b(2), 8.B.8.c(7)</reference>
                  </Group>
                  <Group id="CM-5" hidden="true">
                        <title>Access Restrictions for Change</title>
                        <reference>ISO/IEC 17799: 11.6.1</reference>
                        <reference>NIST 800-26: 6.1.3, 6.1.4, 10.1.1, 10.1.4, 10.1.5</reference>
                        <reference>GAO FISCAM: SD-1.1, SS-1.2, SS-2.1</reference>
                        <reference>DOD 8500.2: DCPR-1, ECSD-2</reference>
                        <reference>DCID 6/3: 5.B.3.a(2)(b)</reference>
                  </Group>
                  <Group id="CM-6" hidden="true">
                        <title>Configuration Settings</title>
                        <reference>NIST 800-26: 10.2.6, 10.3.1, 16.2.2, 16.2.3, 16.2.11</reference>
                        <reference>DOD 8500.2: DCSS-1, ECSC-1, E3.3.8</reference>
                        <reference>DCID 6/3: 4.B.2.a(10)</reference>
                  </Group>
                  <Group id="CM-7" hidden="true">
                        <title>Least Functionality</title>
                        <reference>NIST 800-26: 10.3.1</reference>
                        <reference>DOD 8500.2: DCPP-1, ECIM-1, ECVI-1, E3.3.8</reference>
                        <reference>DCID 6/3: 4.B.2.a(10), 7.D.2.b</reference>
                  </Group>
            </Group>
            <Group id="contingency_planning" hidden="true">
                  <title>Applicable 800-53 Contingency Planning</title>
                  <Group id="CP-1" hidden="true">
                        <title>Contingency Planning Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 5.1.1, 10.4.1, 14.1.1, 14.1.3, 15.1.1</reference>
                        <reference>NIST 800-26: 9</reference>
                        <reference>DOD 8500.2: COBR-1, DCAR-1</reference>
                        <reference>DCID 6/3: 2.B.4.e(5), 6.B.1.a(1)</reference>
                  </Group>
                  <Group id="CP-2" hidden="true">
                        <title>Contingency Plan</title>
                        <reference>ISO/IEC 17799: 10.3.2, 10.4.1, 10.8.5, 14.1.3, 14.1.4</reference>
                        <reference>NIST 800-26: 4.1.4, 9.1.1, 9.2, 9.2.1, 9.2.2, 9.2.3, 9.2.10, 12.1.8, 12.2.2</reference>
                        <reference>GAO FISCAM: SC-3.1, SC-1.1</reference>
                        <reference>DOD 8500.2: CODP-1, COEF-1</reference>
                        <reference>DCID 6/3: 6.B.2.b(1)</reference>
                  </Group>
                  <Group id="CP-3" hidden="true">
                        <title>Contingency Training</title>
                        <reference>ISO/IEC 17799: 14.1.3, 14.1.4</reference>
                        <reference>NIST 800-26: 9.3.2</reference>
                        <reference>GAO FISCAM: SC-2.3</reference>
                        <reference>DOD 8500.2: PRTN-1</reference>
                        <reference>DCID 6/3: 8.B.1</reference>
                  </Group>
                  <Group id="CP-4" hidden="true">
                        <title>Contingency Plan Testing</title>
                        <reference>ISO/IEC 17799: 10.5.1, 14.1.5</reference>
                        <reference>NIST 800-26: 4.1.4, 9.3.3</reference>
                        <reference>GAO FISCAM: SC-3.1</reference>
                        <reference>DOD 8500.2: COED-1</reference>
                        <reference>DCID 6/3: 6.B.3.b(2)(b)</reference>
                  </Group>
                  <Group id="CP-5" hidden="true">
                        <title>Contingency Plan Update</title>
                        <reference>ISO/IEC 17799: 14.1.3, 14.1.5</reference>
                        <reference>NIST 800-26: 9.3.1, 9.3.3, 10.2.12</reference>
                        <reference>GAO FISCAM: SC-2.1, SC-3.1</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: 6.B.3.b(2)</reference>
                  </Group>
                  <Group id="CP-6" hidden="true">
                        <title>Alternate Storage Sites</title>
                        <reference>ISO/IEC 17799: 10.5.1</reference>
                        <reference>NIST 800-26: 9.2.4, 9.2.5, 9.2.7, 9.2.9</reference>
                        <reference>GAO FISCAM: SC-2.1, SC-3.1</reference>
                        <reference>DOD 8500.2: CODB-2</reference>
                        <reference>DCID 6/3: 6.B.2.a(2), 6.B.3.a(2)(d)</reference>
                  </Group>
                  <Group id="CP-7" hidden="true">
                        <title>Alternate Processing Sites</title>
                        <reference>ISO/IEC 17799: 14.1.4</reference>
                        <reference>NIST 800-26: 9.1.3, 9.2.4, 9.2.5, 9.2.7, 9.2.9</reference>
                        <reference>GAO FISCAM: SC-2.1, SC-3.1</reference>
                        <reference>DOD 8500.2: COAS-1, COEB-1, COSP-1, COSP-2</reference>
                        <reference>DCID 6/3: 6.B.3.a(2)(d)</reference>
                  </Group>
                  <Group id="CP-8" hidden="true">
                        <title>Telecommunications Services</title>
                        <reference>ISO/IEC 17799: 14.1.4</reference>
                        <reference>DCID 6/3: 6.B.2.a(4)</reference>
                  </Group>
                  <Group id="CP-9" hidden="true">
                        <title>Information System Backup</title>
                        <reference>ISO/IEC 17799: 10.5.1, 11.7.1</reference>
                        <reference>NIST 800-26: 9.1.1, 9.2.6, 9.2.9, 9.3.1, 12.1.9</reference>
                        <reference>GAO FISCAM: SC-2.1</reference>
                        <reference>DOD 8500.2: CODB-1, CODB-2, COSW-1</reference>
                        <reference>DCID 6/3: 6.B.1.a(2)</reference>
                  </Group>
                  <Group id="CP-10" hidden="true">
                        <title>Information System Recovery and Reconstitution</title>
                        <reference>ISO/IEC 17799: 14.1.4</reference>
                        <reference>NIST 800-26: 9.2.8</reference>
                        <reference>GAO FISCAM: SC-2.1</reference>
                        <reference>DOD 8500.2: COTR-1, ECND-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(4), 6.B.1.a(1), 6.B.2.a(3)(d)</reference>
                  </Group>
            </Group>
            <Group id="identification_and_authentication" hidden="true">
                  <title>Applicable 800-53 Identification and Authentication</title>
                  <Group id="IA-1" hidden="true">
                        <title>Identification and Authentication Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 15.1.1</reference>
                        <reference>NIST 800-26: 11.2.3</reference>
                        <reference>DOD 8500.2: IAIA-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="IA-2" hidden="true">
                        <title>User Identification and Authentication</title>
                        <reference>ISO/IEC 17799: 11.2.3, 11.4.2, 11.5.2</reference>
                        <reference>NIST 800-26: 15.1</reference>
                        <reference>DOD 8500.2: IAIA-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(7)</reference>
                  </Group>
                  <Group id="IA-3" hidden="true">
                        <title>Device Identification and Authentication</title>
                        <reference>ISO/IEC 17799: 11.4.2, 11.4.3, 11.7.1</reference>
                        <reference>NIST 800-26: 16.2.7</reference>
                        <reference>DCID 6/3: 4.B.5.a(14)</reference>
                  </Group>
                  <Group id="IA-4" hidden="true">
                        <title>Identifier Management</title>
                        <reference>ISO/IEC 17799: 11.2.3, 11.5.2</reference>
                        <reference>NIST 800-26: 15.1.1, 15.2.2, 15.1.8</reference>
                        <reference>GAO FISCAM: AC-2.1, AC-3.2, SP-4.1</reference>
                        <reference>DOD 8500.2: IAGA-1, IAIA-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(2)</reference>
                  </Group>
                  <Group id="IA-5" hidden="true">
                        <title>Authenticator Management</title>
                        <reference>ISO/IEC 17799: 11.5.2, 11.5.3</reference>
                        <reference>NIST 800-26: 15.1.6, 15.1.7, 15.1.9, 15.1.10, 15.1.11, 15.1.12, 15.1.13, 16.1.3, 16.2.3</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: IAKM-1, IATS-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(7), 4.B.3.a(11)</reference>
                  </Group>
                  <Group id="IA-6" hidden="true">
                        <title>Authenticator Feedback</title>
                        <reference>ISO/IEC 17799: 11.5.1</reference>
                        <reference>DCID 6/3: 4.B.2.a(7)(g)</reference>
                  </Group>
                  <Group id="IA-7" hidden="true">
                        <title>Cryptographic Module Authentication</title>
                        <reference>NIST 800-26: 16.1.7</reference>
                        <reference>DCID 6/3: 1.G</reference>
                  </Group>
            </Group>
            <Group id="incident_response" hidden="true">
                  <title>Applicable 800-53 Incident Response</title>
                  <Group id="IR-1" hidden="true">
                        <title>Incident Response Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.4.1, 13.1, 13.2.1, 15.1.1</reference>
                        <reference>NIST 800-26: 14</reference>
                        <reference>DOD 8500.2: VIIR-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.c; C.4 Manual: 2.B.4.e(5); 2.B.2.b(6); 2.B.6.c(10); 8.B.7</reference>
                  </Group>
                  <Group id="IR-2" hidden="true">
                        <title>Incident Response Training</title>
                        <reference>ISO/IEC 17799: 13.1.1</reference>
                        <reference>NIST 800-26: 14.1.4</reference>
                        <reference>GAO FISCAM: SP-3.4</reference>
                        <reference>DOD 8500.2: VIIR-1</reference>
                        <reference>DCID 6/3: 8.B.1.b(1)(f), 8.B.1.c(1)(e), 8.B.1.c(2)©</reference>
                  </Group>
                  <Group id="IR-3" hidden="true">
                        <title>Incident Response Testing</title>
                        <reference>ISO/IEC 17799: 14.1.5</reference>
                        <reference>DOD 8500.2: VIIR-1</reference>
                        <reference>DCID 6/3: 8.B.7</reference>
                  </Group>
                  <Group id="IR-4" hidden="true">
                        <title>Incident Handling</title>
                        <reference>ISO/IEC 17799: 6.1.6, 13.2.1, 13.2.2</reference>
                        <reference>NIST 800-26: 2.1.5, 14.1.1, 14.1.2, 14.1.6</reference>
                        <reference>GAO FISCAM: SP-3.4</reference>
                        <reference>DOD 8500.2: VIIR-1, E3.3.9</reference>
                        <reference>DCID 6/3: 8.B.7, 9.B.2.e</reference>
                  </Group>
                  <Group id="IR-5" hidden="true">
                        <title>Incident Monitoring</title>
                        <reference>NIST 800-26: 14.1.3</reference>
                        <reference>DOD 8500.2: VIIR-1</reference>
                        <reference>DCID 6/3: 8.B.7.a</reference>
                  </Group>
                  <Group id="IR-6" hidden="true">
                        <title>Incident Reporting</title>
                        <reference>ISO/IEC 17799: 6.1.6, 6.2.2, 6.2.3, 13.1.1, 13.1.2</reference>
                        <reference>NIST 800-26: 14.1.2, 14.1.3, 14.2.1, 14.2.2, 14.2.3</reference>
                        <reference>DOD 8500.2: VIIR-1, E3.3.9</reference>
                        <reference>DCID 6/3: 8.B.7</reference>
                  </Group>
                  <Group id="IR-7" hidden="true">
                        <title>Incident Response Assistance</title>
                        <reference>ISO/IEC 17799: 14.1.3</reference>
                        <reference>NIST 800-26: 8.1.1, 14.1.1</reference>
                        <reference>GAO FISCAM: SP-3.4</reference>
                        <reference>DCID 6/3: 8.B.7.c</reference>
                  </Group>
            </Group>
            <Group id="maintenance" hidden="true">
                  <title>Applicable 800-53 Maintenance</title>
                  <Group id="MA-1" hidden="true">
                        <title>System Maintenance Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.1.1, 15.1.1</reference>
                        <reference>NIST 800-26: 10</reference>
                        <reference>DOD 8500.2: PRMP-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a Manual: 2.B.4.e(5); 6.B.2.a(5)</reference>
                  </Group>
                  <Group id="MA-2" hidden="true">
                        <title>Periodic Maintenance</title>
                        <reference>ISO/IEC 17799: 9.2.4</reference>
                        <reference>NIST 800-26: 10.1.1, 10.1.3, 10.2.1</reference>
                        <reference>GAO FISCAM: SS-3.1</reference>
                        <reference>DCID 6/3: 6.B.2.a(5), 8.B.8.c</reference>
                  </Group>
                  <Group id="MA-3" hidden="true">
                        <title>Maintenance Tools</title>
                        <reference>NIST 800-26: 10.1.3, 11.2.4</reference>
                        <reference>DCID 6/3: 6.B.3.a(5), 8.B.8.c(4), 8.B.8.c(5)</reference>
                  </Group>
                  <Group id="MA-4" hidden="true">
                        <title>Remote Maintenance</title>
                        <reference>ISO/IEC 17799: 11.4.4</reference>
                        <reference>NIST 800-26: 10.1.1, 17.1.1</reference>
                        <reference>GAO FISCAM: SS-3.1</reference>
                        <reference>DOD 8500.2: EBRP-1</reference>
                        <reference>DCID 6/3: 8.B.8.d</reference>
                  </Group>
                  <Group id="MA-5" hidden="true">
                        <title>Maintenance Personnel</title>
                        <reference>ISO/IEC 17799: 6.2.3, 9.2.4</reference>
                        <reference>NIST 800-26: 10.1.1, 10.1.3</reference>
                        <reference>GAO FISCAM: SS-3.1</reference>
                        <reference>DOD 8500.2: PRMP-1</reference>
                        <reference>DCID 6/3: 8.B.8.a</reference>
                  </Group>
                  <Group id="MA-6" hidden="true">
                        <title>Timely Maintenance</title>
                        <reference>NIST 800-26: 9.1.2</reference>
                        <reference>GAO FISCAM: SC-1.2</reference>
                        <reference>DOD 8500.2: COMS-1, COSP-1</reference>
                        <reference>DCID 6/3: 6.B.2.a(5)</reference>
                  </Group>
            </Group>
            <Group id="media_protection" hidden="true">
                  <title>Applicable 800-53 Media Protection</title>
                  <Group id="MP-1" hidden="true">
                        <title>Media Protection Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.1.1, 10.7, 15.1.1, 15.1.3</reference>
                        <reference>NIST 800-26: 8.2</reference>
                        <reference>DOD 8500.2: PESP-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a Manual: 2.B.6.c(7); 8.B.2</reference>
                  </Group>
                  <Group id="MP-2" hidden="true">
                        <title>Media Access</title>
                        <reference>ISO/IEC 17799: 10.7.3</reference>
                        <reference>NIST 800-26: 8.2.1, 8.2.2, 8.2.3, 8.2.6, 8.2.7</reference>
                        <reference>DOD 8500.2: PEDI-1, PEPF-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(4), 4.B.1.a(1), 4.B.1.a(7)</reference>
                  </Group>
                  <Group id="MP-3" hidden="true">
                        <title>Media Labeling</title>
                        <reference>ISO/IEC 17799: 7.2.2, 10.7.3, 10.8.2, 15.1.3</reference>
                        <reference>NIST 800-26: 8.2.5, 8.2.6, 10.2.9</reference>
                        <reference>DOD 8500.2: ECML-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(4), 8.B.2.a, 8.B.2.c</reference>
                  </Group>
                  <Group id="MP-4" hidden="true">
                        <title>Media Storage</title>
                        <reference>ISO/IEC 17799: 10.7.1, 10.7.2, 10.7.3, 10.7.4, 15.1.3</reference>
                        <reference>NIST 800-26: 7.1.4, 8.2.1, 8.2.2, 8.2.9, 10.1.2</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DOD 8500.2: PESS-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(4), 4.B.1.a(7)</reference>
                  </Group>
                  <Group id="MP-5" hidden="true">
                        <title>Media Transport</title>
                        <reference>ISO/IEC 17799: 10.8.3</reference>
                        <reference>NIST 800-26: 8.2.2, 8.2.4</reference>
                        <reference>DCID 6/3: 2.B.9.b(4)</reference>
                  </Group>
                  <Group id="MP-6" hidden="true">
                        <title>Media Sanitization</title>
                        <reference>ISO/IEC 17799: 9.2.6, 10.7.1, 10.7.2</reference>
                        <reference>NIST 800-26: 3.2.11, 3.2.12, 3.2.13, 8.2.8, 8.2.9, 8.2.10</reference>
                        <reference>GAO FISCAM: AC-3.4</reference>
                        <reference>DOD 8500.2: PECS-1, PEDD-1</reference>
                        <reference>DCID 6/3: 8.B.5, 2.B.9.b(4), 8.B.5.a(4), 8.B.5.d, 8.B.5.e</reference>
                  </Group>
                  <Group id="MP-7" hidden="true">
                        <title>Media Destruction and Disposal</title>
                        <reference>ISO/IEC 17799: </reference>
                        <reference>NIST 800-26: </reference>
                        <reference>GAO FISCAM: </reference>
                        <reference>DOD 8500.2: </reference>
                        <reference>DCID 6/3: </reference>
                  </Group>
            </Group>
            <Group id="physical_and_environmental_protection" hidden="true">
                  <title>Applicable 800-53 Physical and Environmental Protection</title>
                  <Group id="PE-1" hidden="true">
                        <title>Physical and Environmental Protection Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 15.1.1</reference>
                        <reference>NIST 800-26: 7</reference>
                        <reference>DOD 8500.2: PETN-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5); 8.D</reference>
                  </Group>
                  <Group id="PE-2" hidden="true">
                        <title>Physical Access Authorizations</title>
                        <reference>ISO/IEC 17799: 9.1.2, 9.1.6</reference>
                        <reference>NIST 800-26: 7.1.1, 7.1.2</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DOD 8500.2: PECF-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(1), 8.E</reference>
                  </Group>
                  <Group id="PE-3" hidden="true">
                        <title>Physical Access Control</title>
                        <reference>ISO/IEC 17799: 9.1.1, 9.1.2, 9.1.5, 9.1.6, 10.5.1</reference>
                        <reference>NIST 800-26: 7.1.1, 7.1.2, 7.1.5, 7.1.6, 7.1.8</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DOD 8500.2: PEPF-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(1), 8.D.2, 8.E</reference>
                  </Group>
                  <Group id="PE-4" hidden="true">
                        <title>Access Control for Transmission Medium</title>
                        <reference>ISO/IEC 17799: 9.2.3</reference>
                        <reference>NIST 800-26: 7.2.2, 16.2.9</reference>
                        <reference>DCID 6/3: 8.D.2, 4.B.1.a(8)</reference>
                  </Group>
                  <Group id="PE-5" hidden="true">
                        <title>Access Control for Display Medium</title>
                        <reference>ISO/IEC 17799: 9.1.2, 11.3.3</reference>
                        <reference>NIST 800-26: 7.2.1</reference>
                        <reference>DOD 8500.2: PEDI-1, PEPF-1</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2</reference>
                  </Group>
                  <Group id="PE-6" hidden="true">
                        <title>Monitoring Physical Access</title>
                        <reference>ISO/IEC 17799: 9.1.2</reference>
                        <reference>NIST 800-26: 7.1.9</reference>
                        <reference>GAO FISCAM: AC-4</reference>
                        <reference>DOD 8500.2: PEPF-2</reference>
                        <reference>DCID 6/3: 4.B.1.a(1), 8.C.2.a, 8.D.2</reference>
                  </Group>
                  <Group id="PE-7" hidden="true">
                        <title>Visitor Control</title>
                        <reference>ISO/IEC 17799: 9.1.2</reference>
                        <reference>NIST 800-26: 7.1.7, 7.1.11</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DOD 8500.2: PEVC-1</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2, 8.E</reference>
                  </Group>
                  <Group id="PE-8" hidden="true">
                        <title>Access Records</title>
                        <reference>ISO/IEC 17799: 9.1.2</reference>
                        <reference>NIST 800-26: 7.1.9</reference>
                        <reference>GAO FISCAM: AC-4</reference>
                        <reference>DOD 8500.2: PEPF-2, PEVC-1</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2, 8.E</reference>
                  </Group>
                  <Group id="PE-9" hidden="true">
                        <title>Power Equipment and Power Cabling</title>
                        <reference>ISO/IEC 17799: 9.2.2, 9.2.3</reference>
                        <reference>NIST 800-26: 7.1.16</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DCID 6/3: 8.D.2</reference>
                  </Group>
                  <Group id="PE-10" hidden="true">
                        <title>Emergency Shutoff</title>
                        <reference>ISO/IEC 17799: 9.2.2</reference>
                        <reference>DOD 8500.2: PEMS-1</reference>
                        <reference>DCID 6/3: 8.D.2</reference>
                  </Group>
                  <Group id="PE-11" hidden="true">
                        <title>Emergency Power</title>
                        <reference>ISO/IEC 17799: 9.2.2</reference>
                        <reference>NIST 800-26: 7.1.18</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DOD 8500.2: COPS-1, COPS-2, COPS-3</reference>
                        <reference>DCID 6/3: 6.B.2.a(6), 6.B.2.a(7)</reference>
                  </Group>
                  <Group id="PE-12" hidden="true">
                        <title>Emergency Lighting</title>
                        <reference>ISO/IEC 17799: 9.2.2</reference>
                        <reference>DOD 8500.2: PEEL-1</reference>
                        <reference>DCID 6/3: 8.D.2</reference>
                  </Group>
                  <Group id="PE-13" hidden="true">
                        <title>Fire Protection</title>
                        <reference>ISO/IEC 17799: 9.1.4, 9.2.1</reference>
                        <reference>NIST 800-26: 7.1.12</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DOD 8500.2: PEFD-1, PEFS-1</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2</reference>
                  </Group>
                  <Group id="PE-14" hidden="true">
                        <title>Temperature and Humidity Controls</title>
                        <reference>ISO/IEC 17799: 9.2.1, 10.5.1, 10.7.1</reference>
                        <reference>NIST 800-26: 7.1.14, 7.1.15</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DOD 8500.2: PEHC-1, PETC-1</reference>
                        <reference>DCID 6/3: 8.D.2</reference>
                  </Group>
                  <Group id="PE-15" hidden="true">
                        <title>Water Damage Protection</title>
                        <reference>ISO/IEC 17799: 9.1.4, 9.2.1</reference>
                        <reference>NIST 800-26: 7.1.17</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2</reference>
                  </Group>
                  <Group id="PE-16" hidden="true">
                        <title>Delivery and Removal</title>
                        <reference>ISO/IEC 17799: 9.1.6, 9.2.7, 10.7.1</reference>
                        <reference>NIST 800-26: 7.1.3</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DCID 6/3: 8.B.5.e</reference>
                  </Group>
                  <Group id="PE-17" hidden="true">
                        <title>Alternate Work Site</title>
                        <reference>ISO/IEC 17799: 11.7.2</reference>
                        <reference>DOD 8500.2: EBRU-1</reference>
                  </Group>
                  <Group id="PE-18" hidden="true">
                        <title>Location of Information System Components</title>
                        <reference>ISO/IEC 17799: 9.2.1</reference>
                  </Group>
                  <Group id="PE-19" hidden="true">
                        <title>Information Leakage</title>
                  </Group>
            </Group>
            <Group id="planning" hidden="true">
                  <title>Applicable 800-53 Planning</title>
                  <Group id="PL-1" hidden="true">
                        <title>Security Planning Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 6.1, 15.1.1</reference>
                        <reference>NIST 800-26: 5</reference>
                        <reference>DOD 8500.2: DCAR-1, E3.4.6</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="PL-2" hidden="true">
                        <title>System Security Plan</title>
                        <reference>ISO/IEC 17799: 6.1</reference>
                        <reference>NIST 800-26: 4.1.5, 5.1.1, 5.1.2, 12.2.1</reference>
                        <reference>GAO FISCAM: SP-2.1</reference>
                        <reference>DOD 8500.2: DCSD-1</reference>
                        <reference>DCID 6/3: 1.F.6, 2.B.6.c(3), 2.B.7.c(5), 9.E.2.a(1)(d), 9.F.2.a, Appendix C</reference>
                  </Group>
                  <Group id="PL-3" hidden="true">
                        <title>System Security Plan Update</title>
                        <reference>ISO/IEC 17799: 6.1</reference>
                        <reference>NIST 800-26: 3.2.10, 5.2.1</reference>
                        <reference>GAO FISCAM: SP-2.1</reference>
                        <reference>DOD 8500.2: 5.7.5</reference>
                        <reference>DCID 6/3: 2.B.7.c(5)</reference>
                  </Group>
                  <Group id="PL-4" hidden="true">
                        <title>Rules of Behavior</title>
                        <reference>ISO/IEC 17799: 7.1.3, 8.1.3, 15.1.5</reference>
                        <reference>NIST 800-26: 4.1.3, 13.1.1</reference>
                        <reference>DOD 8500.2: PRRB-1</reference>
                        <reference>DCID 6/3: 2.B.9.b</reference>
                  </Group>
                  <Group id="PL-5" hidden="true">
                        <title>Privacy Impact Assessment</title>
                        <reference>ISO/IEC 17799: 15.1.4</reference>
                        <reference>DCID 6/3: DCID: B.3.a; Manual: 8.B.9</reference>
                  </Group>
                  <Group id="PL-6" hidden="true">
                        <title>Security-Related Activity Planning</title>
                        <reference>ISO/IEC 17799: 15.3.1</reference>
                  </Group>
            </Group>
            <Group id="personnel_security" hidden="true">
                  <title>Applicable 800-53 Personnel Security</title>
                  <Group id="PS-1" hidden="true">
                        <title>Personnel Security Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 8.1.1, 15.1.1</reference>
                        <reference>NIST 800-26: 6</reference>
                        <reference>DOD 8500.2: PRRB-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5); 8.E</reference>
                  </Group>
                  <Group id="PS-2" hidden="true">
                        <title>Position Categorization</title>
                        <reference>ISO/IEC 17799: 8.1.2</reference>
                        <reference>NIST 800-26: 6.1.1, 6.1.2</reference>
                        <reference>GAO FISCAM: SD-1.2</reference>
                        <reference>DCID 6/3: 8.E</reference>
                  </Group>
                  <Group id="PS-3" hidden="true">
                        <title>Personnel Screening</title>
                        <reference>ISO/IEC 17799: 8.1.2</reference>
                        <reference>NIST 800-26: 6.2.1, 6.2.3</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: PRAS-1</reference>
                        <reference>DCID 6/3: 2.B.7.c(2), 2.B.8.b(5), 8.E</reference>
                  </Group>
                  <Group id="PS-4" hidden="true">
                        <title>Personnel Termination</title>
                        <reference>ISO/IEC 17799: 8.1.3, 8.3, 11.2.1</reference>
                        <reference>NIST 800-26: 6.1.7</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: 5.12.7</reference>
                        <reference>DCID 6/3: 2.B.9.b(6), 4.B.2.a(3)(e), 8.E</reference>
                  </Group>
                  <Group id="PS-5" hidden="true">
                        <title>Personnel Transfer</title>
                        <reference>ISO/IEC 17799: 8.3.1, 8.3.3, 11.2.1</reference>
                        <reference>NIST 800-26: 6.1.7</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: 5.12.7</reference>
                        <reference>DCID 6/3: 2.B.9.b(6)</reference>
                  </Group>
                  <Group id="PS-6" hidden="true">
                        <title>Access Agreements</title>
                        <reference>ISO/IEC 17799: 6.1.5, 8.1.3</reference>
                        <reference>NIST 800-26: 6.1.5, 6.2.2</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: PRRB-1</reference>
                        <reference>DCID 6/3: 1.E.2, 8.E</reference>
                  </Group>
                  <Group id="PS-7" hidden="true">
                        <title>Third-Party Personnel Security</title>
                        <reference>ISO/IEC 17799: 6.2.1, 6.2.3, 8.1.1, 8.1.2, 8.1.3, 8.2.1, 8.2.2, 11.2.1</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: 5.7.10</reference>
                        <reference>DCID 6/3: 1.A.1, 8.D, 8.E</reference>
                  </Group>
                  <Group id="PS-8" hidden="true">
                        <title>Personnel Sanctions</title>
                        <reference>ISO/IEC 17799: 8.2.3, 11.2.1</reference>
                        <reference>NIST 800-26: 6.1.5</reference>
                        <reference>DOD 8500.2: PRRB-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(3)(e), 8.E</reference>
                  </Group>
            </Group>
            <Group id="risk_assessment" hidden="true">
                  <title>Applicable 800-53 Risk Assessment</title>
                  <Group id="RA-1" hidden="true">
                        <title>Risk Assessment Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 4.1, 15.1.1</reference>
                        <reference>NIST 800-26: 1</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.3.a, Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="RA-2" hidden="true">
                        <title>Security Categorization</title>
                        <reference>ISO/IEC 17799: 7.2.1</reference>
                        <reference>NIST 800-26: 1.1.3, 3.1.1</reference>
                        <reference>GAO FISCAM: SP-1, AC-1.1, AC-1.2</reference>
                        <reference>DOD 8500.2: E3.4.2</reference>
                        <reference>DCID 6/3: 3.C, 3.D, 9.E.2.a(1)(a), 9.E.2.a(1)(d)</reference>
                  </Group>
                  <Group id="RA-3" hidden="true">
                        <title>Risk Assessment</title>
                        <reference>ISO/IEC 17799: 4, 4.1, 4.2, 6.2.1, 10.10.2, 10.10.5, 12.5.1, 12.6.1, 14.1.1, 14.1.2</reference>
                        <reference>NIST 800-26: 1.1.2, 1.1.4, 1.1.5, 1.1.6, 1.2.1, 1.2.2, 1.2.3, 3.1.7, 3.1.8, 4.1.7, 7.1.13, 7.1.19, 12.2.4</reference>
                        <reference>GAO FISCAM: SP-1</reference>
                        <reference>DOD 8500.2: DCDS-1, DCII-1, E3.3.10</reference>
                        <reference>DCID 6/3: 9.B</reference>
                  </Group>
                  <Group id="RA-4" hidden="true">
                        <title>Risk Assessment Update</title>
                        <reference>ISO/IEC 17799: 4.1</reference>
                        <reference>NIST 800-26: 1.1.2, 4.1.2</reference>
                        <reference>GAO FISCAM: SP-1</reference>
                        <reference>DOD 8500.2: DCAR-1, DCII-1</reference>
                        <reference>DCID 6/3: 9.B.4.f, 9.D.1.d</reference>
                  </Group>
                  <Group id="RA-5" hidden="true">
                        <title>Vulnerability Scanning</title>
                        <reference>ISO/IEC 17799: 12.6.1</reference>
                        <reference>NIST 800-26: 10.3.2, 14.2.1</reference>
                        <reference>DOD 8500.2: ECMT-1, VIVM-1</reference>
                        <reference>DCID 6/3: 4.B.3.a(8)(b), 4.B.3.b(6)(b), 9.B.4.e</reference>
                  </Group>
            </Group>
            <Group id="system_and_services_acquisition" hidden="true">
                  <title>Applicable 800-53 System and Services Acquisition</title>
                  <Group id="SA-1" hidden="true">
                        <title>System and Services Acquisition Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 12.1, 15.1.1</reference>
                        <reference>NIST 800-26: 3</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="SA-2" hidden="true">
                        <title>Allocation of Resources</title>
                        <reference>ISO/IEC 17799: 10.3.1</reference>
                        <reference>NIST 800-26: 3.1.2, 3.1.3, 3.1.5, 5.1.3</reference>
                        <reference>DOD 8500.2: DCPB-1, E3.3.4</reference>
                        <reference>DCID 6/3: DCID: C.2.a, Manual: 2.B.4.e(8)</reference>
                  </Group>
                  <Group id="SA-3" hidden="true">
                        <title>Life Cycle Support</title>
                        <reference>NIST 800-26: 3.1</reference>
                        <reference>DOD 8500.2: 5.8.1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 9.E.2</reference>
                  </Group>
                  <Group id="SA-4" hidden="true">
                        <title>Acquisitions</title>
                        <reference>ISO/IEC 17799: 12.1.1</reference>
                        <reference>NIST 800-26: 3.1.6, 3.1.7, 3.1.10, 3.1.11, 3.1.12</reference>
                        <reference>DOD 8500.2: DCAS-1, DCDS-1, DCIT-1, DCMC-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a; C.2.a, Manual: 9.B.4</reference>
                  </Group>
                  <Group id="SA-5" hidden="true">
                        <title>Information System Documentation</title>
                        <reference>ISO/IEC 17799: 10.7.4</reference>
                        <reference>NIST 800-26: 3.2.3, 3.2.4, 3.2.8, 12.1.1, 12.1.2, 12.1.3, 12.1.6, 12.1.7</reference>
                        <reference>GAO FISCAM: CC-2.1</reference>
                        <reference>DOD 8500.2: DCCS-1, DCHW-1, DCID-1, DCSD-1, DCSW-1, ECND-1, DCFA-1</reference>
                        <reference>DCID 6/3: 4.B.2.b(2), 4.B.2.b(3), 4.B.4.b(4), 9.C.3</reference>
                  </Group>
                  <Group id="SA-6" hidden="true">
                        <title>Software Usage Restrictions</title>
                        <reference>ISO/IEC 17799: 15.1.2</reference>
                        <reference>NIST 800-26: 10.2.10, 10.2.13</reference>
                        <reference>GAO FISCAM: SS-3.2, SP-2.1</reference>
                        <reference>DOD 8500.2: DCPD-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(11)</reference>
                  </Group>
                  <Group id="SA-7" hidden="true">
                        <title>User Installed Software</title>
                        <reference>ISO/IEC 17799: 15.1.2</reference>
                        <reference>NIST 800-26: 10.2.10</reference>
                        <reference>GAO FISCAM: SS-3.2</reference>
                        <reference>DCID 6/3: 2.B.9.b(11)</reference>
                  </Group>
                  <Group id="SA-8" hidden="true">
                        <title>Security Engineering Principles</title>
                        <reference>ISO/IEC 17799: 12.1</reference>
                        <reference>NIST 800-26: 3.2.1</reference>
                        <reference>DOD 8500.2: DCBP-1, DCCS-1, E3.4.4</reference>
                        <reference>DCID 6/3: 1.H.1</reference>
                  </Group>
                  <Group id="SA-9" hidden="true">
                        <title>Outsourced Information System Services</title>
                        <reference>ISO/IEC 17799: 6.2.1, 6.2.3, 10.2.1, 10.2.2, 10.6.2</reference>
                        <reference>NIST 800-26: 12.2.3</reference>
                        <reference>DOD 8500.2: DCDS-1, DCID-1 DCIT-1, DCPP-1</reference>
                        <reference>DCID 6/3: 1.B.1, 8.C.2, 8.E</reference>
                  </Group>
                  <Group id="SA-10" hidden="true">
                        <title>Developer Configuration Management</title>
                        <reference>ISO/IEC 17799: 12.5.1, 12.5.2</reference>
                        <reference>GAO FISCAM: SS-3.1, CC-3</reference>
                        <reference>DCID 6/3: 4.B.4.b(4), 8.C.2.a</reference>
                  </Group>
                  <Group id="SA-11" hidden="true">
                        <title>Developer Security Testing</title>
                        <reference>ISO/IEC 17799: 12.5.1, 12.5.2</reference>
                        <reference>NIST 800-26: 3.2.1, 3.2.2, 10.2.5, 12.1.5</reference>
                        <reference>GAO FISCAM: SS-3.1, CC-2.1</reference>
                        <reference>DOD 8500.2: E3.4.4</reference>
                        <reference>DCID 6/3: 4.B.4.b(4)</reference>
                  </Group>
            </Group>
            <Group id="system_and_communications_protection" hidden="true">
                  <title>Applicable 800-53 System and Communication Protection</title>
                  <Group id="SC-1" hidden="true">
                        <title>System and Communications Protection Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.8.1, 15.1.1</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="SC-2" hidden="true">
                        <title>Application Partitioning</title>
                        <reference>ISO/IEC 17799: 11.4.5</reference>
                        <reference>DOD 8500.2: DCPA-1</reference>
                        <reference>DCID 6/3: 4.B.3.b(6)(a), 4.B.4.b(8), 5.B.3.b(2)</reference>
                  </Group>
                  <Group id="SC-3" hidden="true">
                        <title>Security Function Isolation</title>
                        <reference>ISO/IEC 17799: 11.4.5</reference>
                        <reference>DOD 8500.2: DCSP-1</reference>
                        <reference>DCID 6/3: 4.B.3.b(6)(a), 4.B.4.b(8), 5.B.3.b(1), 5.B.3.b(2)</reference>
                  </Group>
                  <Group id="SC-4" hidden="true">
                        <title>Information Remnants</title>
                        <reference>ISO/IEC 17799: 10.8.1</reference>
                        <reference>GAO FISCAM: AC-3.4</reference>
                        <reference>DOD 8500.2: ECRC-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(14)</reference>
                  </Group>
                  <Group id="SC-5" hidden="true">
                        <title>Denial of Service Protection</title>
                        <reference>ISO/IEC 17799: 10.8.4, 13.2.1</reference>
                        <reference>DCID 6/3: 6.B.3.a(6)</reference>
                  </Group>
                  <Group id="SC-6" hidden="true">
                        <title>Resource Priority</title>
                        <reference>DCID 6/3: 6.B.3.a(11)</reference>
                  </Group>
                  <Group id="SC-7" hidden="true">
                        <title>Boundary Protection</title>
                        <reference>ISO/IEC 17799: 11.4.6</reference>
                        <reference>NIST 800-26: 16.2.2, 16.2.7, 16.2.9, 16.2.10, 16.2.11, 16.2.14</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: COEB-1, EBBD-1, ECIM-1, ECVI-1</reference>
                        <reference>DCID 6/3: 4.B.4.a(27), 5.B.3.a(11)(b), 7.A.3, 7.B, 7.C, 7.D</reference>
                  </Group>
                  <Group id="SC-8" hidden="true">
                        <title>Transmission Integrity</title>
                        <reference>ISO/IEC 17799: 10.6.1, 10.8.1, 10.9.1</reference>
                        <reference>NIST 800-26: 11.2.1, 11.2.4, 11.2.9, 16.2.14</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECTM-1</reference>
                        <reference>DCID 6/3: 5.B.3.a(11)</reference>
                  </Group>
                  <Group id="SC-9" hidden="true">
                        <title>Transmission Confidentiality</title>
                        <reference>ISO/IEC 17799: 10.6.1, 10.8.1, 10.9.1</reference>
                        <reference>DOD 8500.2: ECCT-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(8)(a)</reference>
                  </Group>
                  <Group id="SC-10" hidden="true">
                        <title>Network Disconnect</title>
                        <reference>ISO/IEC 17799: 11.5.6</reference>
                        <reference>NIST 800-26: 16.2.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DCID 6/3: 4.B.2.a(17)</reference>
                  </Group>
                  <Group id="SC-11" hidden="true">
                        <title>Trusted Path</title>
                        <reference>ISO/IEC 17799: 10.9.2</reference>
                        <reference>NIST 800-26: 16.2.7</reference>
                        <reference>DCID 6/3: 4.B.4.a(14)</reference>
                  </Group>
                  <Group id="SC-12" hidden="true">
                        <title>Cryptographic Key Establishment and Mgmt.</title>
                        <reference>ISO/IEC 17799: 12.3.1, 12.3.2</reference>
                        <reference>NIST 800-26: 16.1.7, 16.1.8</reference>
                        <reference>DOD 8500.2: IAKM-1</reference>
                        <reference>DCID 6/3: 1.G</reference>
                  </Group>
                  <Group id="SC-13" hidden="true">
                        <title>Use of Validated Cryptography</title>
                        <reference>NIST 800-26: 16.1.7, 16.1.8</reference>
                        <reference>DOD 8500.2: IAKM-1, IATS-1</reference>
                        <reference>DCID 6/3: 1.G.1</reference>
                  </Group>
                  <Group id="SC-14" hidden="true">
                        <title>Public Access Protections</title>
                        <reference>ISO/IEC 17799: 10.7.4, 10.9.3</reference>
                        <reference>DOD 8500.2: EBPW-1</reference>
                  </Group>
                  <Group id="SC-15" hidden="true">
                        <title>Collaborative Computing</title>
                        <reference>DOD 8500.2: ECVI-1</reference>
                        <reference>DCID 6/3: 7.G</reference>
                  </Group>
                  <Group id="SC-16" hidden="true">
                        <title>Transmission of Security Parameters</title>
                        <reference>ISO/IEC 17799: 7.2.2, 10.8.2, 10.9.2</reference>
                        <reference>NIST 800-26: 16.1.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECTM-2</reference>
                        <reference>DCID 6/3: 4.B.1.a(3)</reference>
                  </Group>
                  <Group id="SC-17" hidden="true">
                        <title>Public Key Infrastructure Certificates</title>
                        <reference>ISO/IEC 17799: 12.3.2</reference>
                        <reference>DOD 8500.2: IAKM-1</reference>
                        <reference>DCID 6/3: 2.B.4.e(5), 4.B.3.a(11)</reference>
                  </Group>
                  <Group id="SC-18" hidden="true">
                        <title>Mobile Code</title>
                        <reference>ISO/IEC 17799: 10.4.1, 10.4.2</reference>
                        <reference>DOD 8500.2: DCMC-1</reference>
                        <reference>DCID 6/3: 2.B.4.e(5), 7.E</reference>
                  </Group>
                  <Group id="SC-19" hidden="true">
                        <title>Voice Over Internet Protocol</title>
                        <reference>DOD 8500.2: ECVI-1</reference>
                        <reference>DCID 6/3: DCID 6/3 2.B.4.d, 9.D.1.a</reference>
                  </Group>
                  <Group id="SC-20" hidden="true">
                        <title>Secure Name Address Resolution Service (Authoritative Source)</title>
                  </Group>
                  <Group id="SC-21" hidden="true">
                        <title>Secure Name Address Resolution Service (Resolution)</title>
                  </Group>
                  <Group id="SC-22" hidden="true">
                        <title>Architecture and Provisioning for Name/Address Resolution Service</title>
                  </Group>
                  <Group id="SC-23" hidden="true">
                        <title>Session Authenticity</title>
                  </Group>
            </Group>
            <Group id="system_and_information_integrity" hidden="true">
                  <title>Applicable 800-53 System and Information Integrity</title>
                  <Group id="SI-1" hidden="true">
                        <title>System and Information Integrity Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 15.1.1</reference>
                        <reference>NIST 800-26: 11</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5), 5.B.1.b(1), 5.B.2.a(5)(a)(1)</reference>
                  </Group>
                  <Group id="SI-2" hidden="true">
                        <title>Flaw Remediation</title>
                        <reference>ISO/IEC 17799: 10.10.5, 12.4.1, 12.5.1, 12.5.2, 12.6.1</reference>
                        <reference>NIST 800-26: 10.3.2, 11.1.1, 11.1.2, 11.2.2, 11.2.7</reference>
                        <reference>GAO FISCAM: SS-2.2</reference>
                        <reference>DOD 8500.2: DCSQ-1, DCCT-1, VIVM-1</reference>
                        <reference>DCID 6/3: 5.B.2.a(5)(a)(3), 6.B.2.a(5)</reference>
                  </Group>
                  <Group id="SI-3" hidden="true">
                        <title>Malicious Code Protection</title>
                        <reference>ISO/IEC 17799: 10.4.1</reference>
                        <reference>NIST 800-26: 11.1.1, 11.1.2</reference>
                        <reference>DOD 8500.2: ECVP-1, VIVM-1</reference>
                        <reference>DCID 6/3: 5.B.1.a(4), 7.B.4.b(1)</reference>
                  </Group>
                  <Group id="SI-4" hidden="true">
                        <title>Information System Monitoring Tools and Techniques</title>
                        <reference>ISO/IEC 17799: 10.6.2, 10.10.1, 10.10.2, 10.10.4</reference>
                        <reference>NIST 800-26: 11.2.5, 11.2.6</reference>
                        <reference>DOD 8500.2: EBBD-1, EBVC-1, ECID-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(5)(b), 4.B.3.a(8)(b), 6.B.3.a(8)</reference>
                  </Group>
                  <Group id="SI-5" hidden="true">
                        <title>Security Alerts and Advisories</title>
                        <reference>ISO/IEC 17799: 6.1.7, 10.4.1</reference>
                        <reference>NIST 800-26: 14.1.1, 14.1.2, 14.1.5</reference>
                        <reference>GAO FISCAM: SP-3.4</reference>
                        <reference>DOD 8500.2: VIVM-1</reference>
                        <reference>DCID 6/3: 8.B.7</reference>
                  </Group>
                  <Group id="SI-6" hidden="true">
                        <title>Security Functionality Verification</title>
                        <reference>NIST 800-26: 11.2.1, 11.2.2</reference>
                        <reference>GAO FISCAM: SS-2.2</reference>
                        <reference>DOD 8500.2: DCSS-1</reference>
                        <reference>DCID 6/3: 4.B.1.c(2), 5.B.2.b(2)</reference>
                  </Group>
                  <Group id="SI-7" hidden="true">
                        <title>Software and Information Integrity</title>
                        <reference>ISO/IEC 17799: 12.2.1, 12.2.2, 12.2.4</reference>
                        <reference>NIST 800-26: 11.2.1, 11.2.4</reference>
                        <reference>DOD 8500.2: ECSD-2</reference>
                        <reference>DCID 6/3: 4.B.1.c(2), 5.B.1.a(3), 5.B.2.a(6)</reference>
                  </Group>
                  <Group id="SI-8" hidden="true">
                        <title>Spam Protection</title>
                        <reference>DCID 6/3: 5.B.1.a(4)</reference>
                  </Group>
                  <Group id="SI-9" hidden="true">
                        <title>Information Input Restrictions</title>
                        <reference>ISO/IEC 17799: 12.2.1, 12.2.2</reference>
                        <reference>GAO FISCAM: SD-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(11)</reference>
                  </Group>
                  <Group id="SI-10" hidden="true">
                        <title>Information Accuracy, Completeness, Validity, and Authenticity</title>
                        <reference>ISO/IEC 17799: 10.7.3, 12.2.1, 12.2.2</reference>
                        <reference>DCID 6/3: 7.B.2.h, 2.B.4.d</reference>
                  </Group>
                  <Group id="SI-11" hidden="true">
                        <title>Error Handling</title>
                        <reference>ISO/IEC 17799: 12.2.1, 12.2.2, 12.2.3, 12.2.4</reference>
                        <reference>DCID 6/3: 2.B.4.d</reference>
                  </Group>
                  <Group id="SI-12" hidden="true">
                        <title>Information Output Handling and Retention</title>
                        <reference>ISO/IEC 17799: 10.7.3, 12.2.4</reference>
                        <reference>DOD 8500.2: PESP-1</reference>
                        <reference>DCID 6/3: 2.B.4.d, 8.B.9, 8.G</reference>
                  </Group>
            </Group>
      </Group>
      <!-- ==================================================================================================== -->
      <!-- =====================================  FDCC SECURITY GUIDANCE  ===================================== -->
      <!-- ==================================================================================================== -->
      <!--                                                                                                      -->
      <!-- The following groups represent the collection of FDCC guidance for Microsoft Internet Explorer 7.    -->
      <!-- For specific recommendations regarding which rules to enable and which values to use, please refer   -->
      <!-- to the XCCDF profiles above.                                                                         -->
      <!--                                                                                                      -->
      <!-- **************************************************************************************************** -->
      <!-- ***  1 - Introduction                                                                            *** -->
      <!-- **************************************************************************************************** -->
      <Group id="introduction">
            <title>Introduction</title>
            <description>This guide has been created to assist federal agencies in effectively securing systems with Microsoft Windows Internet Explorer 7 based on OMB Federal Desktop Core Configuration recommendations.<xhtml:br/><xhtml:br/>Under the direction of OMB and in collaboration with DHS, DISA, NSA, USAF, and Microsoft, NIST has provided the following baseline to help agencies test, implement, and deploy the Microsoft Windows Internet Explorer 7 Federal Desktop Core Configuration (FDCC) baseline. The Federal Desktop Core Configuration (FDCC) is an OMB-mandated security configuration.<xhtml:br/><xhtml:br/>Please refer to the FDCC home page for additional information. http://fdcc.nist.gov</description>
      </Group>
      <!-- **************************************************************************************************** -->
      <!-- ***  2 - FDCC Security Settings                                                                  *** -->
      <!-- **************************************************************************************************** -->
      <!--                                                                                                      -->
      <!-- none                                                                                                 -->
      <!--                                                                                                      -->
      <!-- **************************************************************************************************** -->
      <!-- ***  3 - FDCC Other Settings                                                                     *** -->
      <!-- **************************************************************************************************** -->
      <Group id="fdcc_other_settings">
            <title>FDCC Other Settings</title>
            <description>FDCC has identified the following additional controls that must be checked in order to verify compliance.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  Local Computer Policy                                                                     -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="local-computer-policy">
                  <title>Local Computer Policy</title>
                  <description>todo - description needed</description>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--                     Core Policy                     -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="core-policy">
                        <title>Core Policy</title>
                        <description>The following are some additional settings for Microsoft Internet Explorer 7</description>
                        <Value id="DisableConfiguringHistory_LocalComputer_1_var" type="number" operator="equals">
                              <title>DisableConfiguringHistory_LocalComputer_1_var</title>
                              <description>DisableConfiguringHistory_LocalComputer_1_var</description>
                              <value>1</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="DisableConfiguringHistory_LocalComputer_2_var" type="number" operator="equals">
                              <title>DisableConfiguringHistory_LocalComputer_2_var</title>
                              <description>DisableConfiguringHistory_LocalComputer_2_var</description>
                              <value>40</value>
                              <value selector="40_days">40</value>
                        </Value>
                        <Value id="DisableAutomaticInstallOfIEComponents_LocalComputer_var" type="number" operator="equals">
                              <title>DisableAutomaticInstallOfIEComponents_LocalComputer_var</title>
                              <description>DisableAutomaticInstallOfIEComponents_LocalComputer_var</description>
                              <value>1</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="DisableChangingAutomaticConfigurationSettings_LocalComputer_var" type="number" operator="equals">
                              <title>DisableChangingAutomaticConfigurationSettings_LocalComputer_var</title>
                              <description>DisableChangingAutomaticConfigurationSettings_LocalComputer_var</description>
                              <value>1</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="DisablePeriodicCheckForIESoftwareUpdates_LocalComputer_var" type="number" operator="equals">
                              <title>DisablePeriodicCheckForIESoftwareUpdates_LocalComputer_var</title>
                              <description>DisablePeriodicCheckForIESoftwareUpdates_LocalComputer_var</description>
                              <value>1</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="DisableShowingSplashScreen_LocalComputer_var" type="number" operator="equals">
                              <title>DisableShowingSplashScreen_LocalComputer_var</title>
                              <description>DisableShowingSplashScreen_LocalComputer_var</description>
                              <value>1</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="DisableSoftwareUpdateShellNotifications_LocalComputer_var" type="number" operator="equals">
                              <title>DisableSoftwareUpdateShellNotifications_LocalComputer_var</title>
                              <description>DisableSoftwareUpdateShellNotifications_LocalComputer_var</description>
                              <value>1</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="DoNotAllowUsersEnableDisableAddOns_LocalComputer_var" type="number" operator="equals">
                              <title>DoNotAllowUsersEnableDisableAddOns_LocalComputer_var</title>
                              <description>DoNotAllowUsersEnableDisableAddOns_LocalComputer_var</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                        </Value>
                        <Value id="MakeProxySettingsPerMachine_LocalComputer_var" type="number" operator="equals">
                              <title>MakeProxySettingsPerMachine_LocalComputer_var</title>
                              <description>MakeProxySettingsPerMachine_LocalComputer_var</description>
                              <value>1</value>
                              <value selector="disabled">1</value>
                              <value selector="enabled">0</value>
                        </Value>
                        <Value id="PreventParticipationInCustomerExperienceImprovementPrograms_LocalComputer_var" type="number" operator="equals">
                              <title>PreventParticipationInCustomerExperienceImprovementPrograms_LocalComputer_var</title>
                              <description>PreventParticipationInCustomerExperienceImprovementPrograms_LocalComputer_var</description>
                              <value>0</value>
                              <value selector="disabled">1</value>
                              <value selector="enabled">0</value>
                        </Value>
                        <Value id="PreventPerformanceOfFirstRunCustomizeSettings_LocalComputer_var" type="number" operator="equals">
                              <title>PreventPerformanceOfFirstRunCustomizeSettings_LocalComputer_var</title>
                              <description>PreventPerformanceOfFirstRunCustomizeSettings_LocalComputer_var</description>
                              <value>1</value>
                              <value selector="enabled:home_page">1</value>
                              <value selector="enabled:welcome_page">2</value>
                        </Value>
                        <Value id="DoNotAllowUsersAddDeleteSites_LocalComputer_var" type="number" operator="equals">
                              <title>DoNotAllowUsersAddDeleteSites_LocalComputer_var</title>
                              <description>DoNotAllowUsersAddDeleteSites_LocalComputer_var</description>
                              <value>1</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="DoNotAllowUsersChangePolicies_LocalComputer_var" type="number" operator="equals">
                              <title>DoNotAllowUsersChangePolicies_LocalComputer_var</title>
                              <description>DoNotAllowUsersChangePolicies_LocalComputer_var</description>
                              <value>1</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="use_only_machine_settings_local_computer_var" type="number" operator="equals">
                              <title>use_only_machine_settings_local_computer_var</title>
                              <description>use_only_machine_settings_local_computer_var</description>
                              <value>1</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="TurnOffDeleteBrowsingHistoryFunctionality_LocalComputer_var" type="number" operator="equals">
                              <title>TurnOffDeleteBrowsingHistoryFunctionality_LocalComputer_var</title>
                              <description>TurnOffDeleteBrowsingHistoryFunctionality_LocalComputer_var</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="TurnOffCrashDetection_LocalComputer_var" type="number" operator="equals">
                              <title>TurnOffCrashDetection_LocalComputer_var</title>
                              <description>TurnOffCrashDetection_LocalComputer_var</description>
                              <value>1</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="TurnOffManagingPhishingFilter_LocalComputer_var" type="number" operator="equals">
                              <title>TurnOffManagingPhishingFilter_LocalComputer_var</title>
                              <description>TurnOffManagingPhishingFilter_LocalComputer_var</description>
                              <value>0</value>
                              <value selector="enabled:off">0</value>
                              <value selector="enabled:manual">1</value>
                              <value selector="enabled:automatic">2</value>
                        </Value>
                        <Value id="TurnOffSecuritySettingsCheckFeature_LocalComputer_var" type="number" operator="equals">
                              <title>TurnOffSecuritySettingsCheckFeature_LocalComputer_var</title>
                              <description>TurnOffSecuritySettingsCheckFeature_LocalComputer_var</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="DisableConfiguringHistory_LocalComputer" selected="false" weight="10.0">
                              <title>Disable "Configuring History" - Local Computer</title>
                              <description>This setting specifies the number of days that Internet Explorer keeps track of the pages viewed in the History List. The delete Browsing History option can be accessed using Tools, Internet Options and General tab.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4001-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-66</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="DisableConfiguringHistory_LocalComputer_1_var" export-name="oval:gov.nist.fdcc.ie7:var:67"/>
                                    <check-export value-id="DisableConfiguringHistory_LocalComputer_2_var" export-name="oval:gov.nist.fdcc.ie7:var:107"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:757"/>
                              </check>
                        </Rule>
                        <Rule id="DisableAutomaticInstallOfIEComponents_LocalComputer" selected="false" weight="10.0">
                              <title>Disable Automatic Install of Internet Explorer Components - Local Computer</title>
                              <description>This Disable Automatic Install of Internet Explorer components setting prevents Internet Explorer from automatically installing components.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                              </reference>
                              <requires idref="SI-3"/>
                              <requires idref="SI-7"/>
                              <requires idref="SI-8"/>
                              <ident system="http://cce.mitre.org">CCE-3518-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-684</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="DisableAutomaticInstallOfIEComponents_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:273"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1198"/>
                              </check>
                        </Rule>
                        <Rule id="DisableChangingAutomaticConfigurationSettings_LocalComputer" selected="false" weight="10.0">
                              <title>Disable Changing Automatic Configuration Settings - Local Computer</title>
                              <description>This Disable Automatic Install of Internet Explorer components setting prevents Internet Explorer from automatically installing components.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                              </reference>
                              <requires idref="CM-5"/>
                              <ident system="http://cce.mitre.org">CCE-4147-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-471</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="DisableChangingAutomaticConfigurationSettings_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:140"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1285"/>
                              </check>
                        </Rule>
                        <Rule id="DisablePeriodicCheckForIESoftwareUpdates_LocalComputer" selected="false" weight="10.0">
                              <title>Disable Periodic Check For Internet Explorer Software Updates - Local Computer</title>
                              <description>The Disable Periodic Check for Internet Explorer software updates setting prevents Internet Explorer from more frequently checking whether a new browser update is available.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3576-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-212</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="DisablePeriodicCheckForIESoftwareUpdates_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:543"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1357"/>
                              </check>
                        </Rule>
                        <Rule id="DisableShowingSplashScreen_LocalComputer" selected="false" weight="10.0">
                              <title>Disable Showing the Splash Screen - Local Computer</title>
                              <description>The Disable showing the splash screen setting prevents the Internet Explorer splash screen from appearing when users start the browser. Enabling this policy causes the splash screen, which normally displays the program name, licensing, and copyright information</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3706-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-556</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="DisableShowingSplashScreen_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:298"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1164"/>
                              </check>
                        </Rule>
                        <Rule id="DisableSoftwareUpdateShellNotifications_LocalComputer" selected="false" weight="10.0">
                              <title>Disable Software Update Shell Notifications on Program Launch - Local Computer</title>
                              <description>The Disable software update shell notifications on program launch setting specifies that programs using the Microsoft Software Distribution Channel will not notify users when they install new components.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                              </reference>
                              <requires idref="CM-4"/>
                              <ident system="http://cce.mitre.org">CCE-4118-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-622</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="DisableSoftwareUpdateShellNotifications_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:977"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1188"/>
                              </check>
                        </Rule>
                        <Rule id="DoNotAllowUsersEnableDisableAddOns_LocalComputer" selected="false" weight="10.0">
                              <title>Do Not Allow Users to enable or Disable Add-Ons - Local Computer</title>
                              <description>The Do not allow users to enable or disable add-ons policy setting allows you to manage whether users have the ability to allow or deny add-ons through Manage Add-ons. If you configure this policy setting to Enabled, users cannot enable or disable add-ons. This item is disabled.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                              </reference>
                              <requires idref="CM-5"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-3744-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-708</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="DoNotAllowUsersEnableDisableAddOns_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:962"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1694"/>
                              </check>
                        </Rule>
                        <Rule id="MakeProxySettingsPerMachine_LocalComputer" selected="false" weight="10.0">
                              <title>Make proxy settings per-machine (rather than per-user) - Local Computer</title>
                              <description>The Make proxy settings per – machine (rather than per-user) setting ensures proxy settings for all users of the same computer are the same.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                              </reference>
                              <requires idref="CM-5"/>
                              <ident system="http://cce.mitre.org">CCE-3201-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-693</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="MakeProxySettingsPerMachine_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:710"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1181"/>
                              </check>
                        </Rule>
                        <Rule id="PreventParticipationInCustomerExperienceImprovementPrograms_LocalComputer" selected="false" weight="10.0">
                              <title>Prevent participation in the Customer Experience Improvement Programs - Local Computer</title>
                              <description>This policy setting prevents users from participating in the Customer Experience Improvement Program (CEIP).</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                              </reference>
                              <requires idref="AC-4"/>
                              <ident system="http://cce.mitre.org">CCE-3993-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-495</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="PreventParticipationInCustomerExperienceImprovementPrograms_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:821"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1171"/>
                              </check>
                        </Rule>
                        <Rule id="PreventPerformanceOfFirstRunCustomizeSettings_LocalComputer" selected="false" weight="10.0">
                              <title>Prevent performance of First Run Customize settings - Local Computer</title>
                              <description>This policy setting prevents performance of the First Run Customize settings ability and controls what the user will see when they launch Internet Explorer for the first time after installation of Internet Explorer.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                              </reference>
                              <requires idref="SI-3"/>
                              <ident system="http://cce.mitre.org">CCE-3207-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1006</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="PreventPerformanceOfFirstRunCustomizeSettings_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:145"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1322"/>
                              </check>
                        </Rule>
                        <Rule id="DoNotAllowUsersAddDeleteSites_LocalComputer" selected="false" weight="10.0">
                              <title>Security Zones: Do Not Allow Users to Add/Delete Sites - Local Computer</title>
                              <description>The Security Zones: Do not allow users to add/delete sites setting prevents users from adding or removing sites from security zones. A security zone is a group of Web sites with the same security level.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                              </reference>
                              <requires idref="SC-11"/>
                              <ident system="http://cce.mitre.org">CCE-3929-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-146</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="DoNotAllowUsersAddDeleteSites_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:287"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1400"/>
                              </check>
                        </Rule>
                        <Rule id="DoNotAllowUsersChangePolicies_LocalComputer" selected="false" weight="10.0">
                              <title>Security Zones: Do Not Allow Users to Change Policies - Local Computer</title>
                              <description>The Security Zones: Do not allow users to change policies setting prevents users from changing security zone settings. A security zone is a group of Web sites with the same security level.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                              </reference>
                              <requires idref="CM-5"/>
                              <requires idref="AC-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-3933-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-833</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="DoNotAllowUsersChangePolicies_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:167"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1404"/>
                              </check>
                        </Rule>
                        <Rule id="use_only_machine_settings_local_computer" selected="false" weight="10.0">
                              <title>Security Zones: Use Only Machine Settings - Local Computer</title>
                              <description>Applies security zone information to all users of the same computer. A security zone is a group of Web sites with the same security level. If you enable this policy, changes that the user makes to a security zone will apply to all users of that computer.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                              </reference>
                              <requires idref="CM-2"/>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4017-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-5</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="use_only_machine_settings_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:580"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1277"/>
                              </check>
                        </Rule>
                        <Rule id="TurnOffDeleteBrowsingHistoryFunctionality_LocalComputer" selected="false" weight="10.0">
                              <title>Turn Off "Delete Browsing History" functionality - Local Computer</title>
                              <description>This policy setting prevents users from performing the "Delete Browsing History" action in Internet Explorer. If you enable this policy setting, users cannot perform the "Delete Browsing History" action in Internet Options for Internet Explorer 7.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                              </reference>
                              <requires idref="AU-9"/>
                              <ident system="http://cce.mitre.org">CCE-3615-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1010</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="TurnOffDeleteBrowsingHistoryFunctionality_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:575"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:458"/>
                              </check>
                        </Rule>
                        <Rule id="TurnOffCrashDetection_LocalComputer" selected="false" weight="10.0">
                              <title>Turn Off Crash Detection - Local Computer</title>
                              <description>The Turn off Crash Detection policy setting allows you to manage the crash detection feature of add-on management in Internet Explorer.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                              </reference>
                              <requires idref="CM-4"/>
                              <ident system="http://cce.mitre.org">CCE-3894-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-753</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="TurnOffCrashDetection_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:346"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:487"/>
                              </check>
                        </Rule>
                        <Rule id="TurnOffManagingPhishingFilter_LocalComputer" selected="false" weight="10.0">
                              <title>Turn Off Managing Phishing Filter - Local Computer</title>
                              <description>This policy setting allows the user to enable a phishing filter that will warn if the Web site being visited is known for fraudulent attempts to gather personal information through "phishing."</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                              </reference>
                              <requires idref="SI-8"/>
                              <ident system="http://cce.mitre.org">CCE-3866-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1032</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="TurnOffManagingPhishingFilter_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:40"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:501"/>
                              </check>
                        </Rule>
                        <Rule id="TurnOffSecuritySettingsCheckFeature_LocalComputer" selected="false" weight="10.0">
                              <title>Turn Off the Security Settings Check Feature - Local Computer</title>
                              <description>This policy setting turns off the Security Settings Check feature, which checks Internet Explorer security settings to determine when the settings put Internet Explorer at risk.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                              </reference>
                              <requires idref="SI-6"/>
                              <ident system="http://cce.mitre.org">CCE-3875-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1054</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="TurnOffSecuritySettingsCheckFeature_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:128"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:916"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--            Internet Control Panel Policy            -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="internet_control_panel_policy">
                        <title>Internet Control Panel - Local Computer</title>
                        <description>todo - description needed</description>
                        <Value id="prevent_ignoring_certificate_errors_local_computer_var" type="number" operator="equals">
                              <title>prevent_ignoring_certificate_errors_local_computer_var</title>
                              <description>prevent_ignoring_certificate_errors_local_computer_var</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="prevent_ignoring_certificate_errors_local_computer" selected="false" weight="10.0">
                              <title>Prevent ignoring certificate errors - Local Computer</title>
                              <description>Internet Explorer treats as fatal any Secure Socket Layer/Transport Layer Security (SSL/TLS) certificate errors that interrupt navigation (such as "expired," "revoked," or "name mismatch" errors).</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel</dc:source>
                              </reference>
                              <requires idref="SI-6"/>
                              <ident system="http://cce.mitre.org">CCE-4199-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-938</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="prevent_ignoring_certificate_errors_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:291"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:655"/>
                              </check>
                        </Rule>
                        <Group id="advanced-page-policy">
                              <title>Advanced Page - Local Computer</title>
                              <description>Advanced Page - Local Computer</description>
                              <Value id="AllowActiveContentFromCD_LocalComputer_var" type="number" operator="equals">
                                    <title>Allow active content from CDs to run on user machines - Local Computer - variable</title>
                                    <description>Allow Active Content from CD's to Run on User Machine - Local Computer - variable</description>
                                    <value>0</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Value id="allow_install_on_demand_ie_local_computer_var" type="number" operator="equals">
                                    <title>Allow Install OnDemand (Internet Explorer) - Local Computer - variable</title>
                                    <description>todo - description needed</description>
                                    <value>0</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Value id="AllowSoftwareRunInstallSignatureInvalid_LocalComputer_var" type="number" operator="equals">
                                    <title>Allow Software to Run or Install Even if the Signature is Invalid - Local Computer - variable</title>
                                    <description>Allow Software to Run or Install Even if the Signature is Invalid - Local Computer - variable</description>
                                    <value>0</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Value id="AllowThird-PartyBrowserExtensions_LocalComputer_var" type="string" operator="equals">
                                    <title>Allow Software to Run or Install Even if the Signature is Invalid - Local Computer - variable</title>
                                    <description>Allow Software to Run or Install Even if the Signature is Invalid - Local Computer - variable</description>
                                    <value>no</value>
                                    <value selector="disabled">no</value>
                                    <value selector="enabled">yes</value>
                              </Value>
                              <Value id="AutomaticallyCheckIEUpdates_LocalComputer_var" type="number" operator="equals">
                                    <title>Allow Third-Party Browser Extensions - Local Computer - variable</title>
                                    <description>Allow Third-Party Browser Extensions - Local Computer - variable</description>
                                    <value>1</value>
                                    <value selector="disabled">1</value>
                                    <value selector="enabled">0</value>
                              </Value>
                              <Value id="CheckServerCertificateRevocation_LocalComputer_var" type="number" operator="equals">
                                    <title>Check for Server Certificate Revocation - Local Computer - variable</title>
                                    <description>Check for Server Certificate Revocation - Local Computer - variable</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Value id="CheckSignatureDownloadedPrograms_LocalComputer_var" type="string" operator="equals">
                                    <title>Check for signatures on downloaded programs - Local Computer - variable</title>
                                    <description>Check for Signature on Downloaded Programs - Local Computer - variable</description>
                                    <value>yes</value>
                                    <value selector="disabled">no</value>
                                    <value selector="enabled">yes</value>
                              </Value>
                              <Value id="DoNotAllowResettingIESettings_LocalComputer_var" type="number" operator="equals">
                                    <title>Do Not Allow Resetting Internet Explorer Settings - Local Computer - variable</title>
                                    <description>Do Not Allow Resetting Internet Explorer Settings - Local Computer - variable</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Rule id="AllowActiveContentFromCD_LocalComputer" selected="false" weight="10.0">
                                    <title>Allow Active Content from CDs to Run on User Machine - Local Computer</title>
                                    <description>This policy setting allows you to manage whether users receive a dialog requesting permission for active content on a CD to run. If you enable this policy setting, active content on a CD will run without a prompt.</description>
                                    <reference>
                                          <dc:type>GPO</dc:type>
                                          <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page</dc:source>
                                    </reference>
                                    <requires idref="SI-7"/>
                                    <requires idref="CM-5"/>
                                    <ident system="http://cce.mitre.org">CCE-4174-9</ident>
                                    <ident system="cce.mitre.org/version/4">CCE-964</ident>
                                    <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                          <check-export value-id="AllowActiveContentFromCD_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:655"/>
                                          <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:400"/>
                                    </check>
                              </Rule>
                              <Rule id="allow_install_on_demand_ie_local_computer" selected="false" weight="10.0" role="unchecked">
                                    <title>Allow Install On Demand (Internet Explorer)</title>
                                    <description>The "Allow Install On Demand (Internet Explorer)" setting should be configured correctly.</description>
                                    <reference>
                                          <dc:type>GPO</dc:type>
                                          <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page</dc:source>
                                    </reference>
                                    <requires idref="SI-7"/>
                                    <requires idref="CM-5"/>
                                    <ident system="http://cce.mitre.org">CCE-3677-2</ident>
                                    <ident system="cce.mitre.org/version/4">CCE-69</ident>
                                    <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                          <!--<check-export value-id="allow_install_on_demand_ie_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:9999"/>-->
                                          <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:9999"/>
                                    </check>
                              </Rule>
                              <Rule id="AllowSoftwareRunInstallSignatureInvalid_LocalComputer" selected="false" weight="10.0">
                                    <title>Allow Software to Run or Install Even if the Signature is Invalid - Local Computer</title>
                                    <description>Microsoft ActiveX controls and file downloads often have digital signatures attached that vouch for both the file's integrity and the identity of the signer (creator) of the software. Such signatures help ensure that unmodified.</description>
                                    <reference>
                                          <dc:type>GPO</dc:type>
                                          <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page</dc:source>
                                    </reference>
                                    <requires idref="SI-7"/>
                                    <requires idref="CM-5"/>
                                    <ident system="http://cce.mitre.org">CCE-3941-2</ident>
                                    <ident system="cce.mitre.org/version/4">CCE-449</ident>
                                    <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                          <check-export value-id="AllowSoftwareRunInstallSignatureInvalid_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:762"/>
                                          <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:680"/>
                                    </check>
                              </Rule>
                              <Rule id="AllowThird-PartyBrowserExtensions_LocalComputer" selected="false" weight="10.0">
                                    <title>Allow Third-Party Browser Extensions - Local Computer</title>
                                    <description>This policy setting allows you to manage whether Internet Explorer will launch COM add-ons known as browser helper objects, such as toolbars.</description>
                                    <reference>
                                          <dc:type>GPO</dc:type>
                                          <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page</dc:source>
                                    </reference>
                                    <requires idref="CM-5"/>
                                    <requires idref="SI-3"/>
                                    <ident system="http://cce.mitre.org">CCE-4192-1</ident>
                                    <ident system="cce.mitre.org/version/4">CCE-598</ident>
                                    <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                          <check-export value-id="AllowThird-PartyBrowserExtensions_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:590"/>
                                          <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:110"/>
                                    </check>
                              </Rule>
                              <Rule id="AutomaticallyCheckIEUpdates_LocalComputer" selected="false" weight="10.0">
                                    <title>Automatically Check for Internet Explorer Updates - Local Computer</title>
                                    <description>This policy setting allows you to manage whether Internet Explorer checks the Internet for newer versions.</description>
                                    <reference>
                                          <dc:type>GPO</dc:type>
                                          <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page</dc:source>
                                    </reference>
                                    <requires idref="CM-6"/>
                                    <ident system="http://cce.mitre.org">CCE-3584-0</ident>
                                    <ident system="cce.mitre.org/version/4">CCE-1008</ident>
                                    <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                          <check-export value-id="AutomaticallyCheckIEUpdates_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:802"/>
                                          <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:656"/>
                                    </check>
                              </Rule>
                              <Rule id="CheckServerCertificateRevocation_LocalComputer" selected="false" weight="10.0">
                                    <title>Check for Server Certificate Revocation - Local Computer</title>
                                    <description>This policy setting allows you to manage whether Internet Explorer will check revocation status of servers' certificates.</description>
                                    <reference>
                                          <dc:type>GPO</dc:type>
                                          <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page</dc:source>
                                    </reference>
                                    <requires idref="SC-17"/>
                                    <requires idref="IA-5"/>
                                    <ident system="http://cce.mitre.org">CCE-3976-8</ident>
                                    <ident system="cce.mitre.org/version/4">CCE-690</ident>
                                    <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                          <check-export value-id="CheckServerCertificateRevocation_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:173"/>
                                          <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:172"/>
                                    </check>
                              </Rule>
                              <Rule id="CheckSignatureDownloadedPrograms_LocalComputer" selected="false" weight="10.0">
                                    <title>Check for signatures on downloaded programs - Local Computer - variable</title>
                                    <description>This policy setting allows you to manage whether Internet Explorer checks for digital signatures (which identifies the publisher of signed software and verifies it hasn't been modified or tampered with) on user computers before downloading executable programs.</description>
                                    <reference>
                                          <dc:type>GPO</dc:type>
                                          <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page</dc:source>
                                    </reference>
                                    <requires idref="SC-17"/>
                                    <requires idref="IA-5"/>
                                    <ident system="http://cce.mitre.org">CCE-4026-1</ident>
                                    <ident system="cce.mitre.org/version/4">CCE-1025</ident>
                                    <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                          <check-export value-id="CheckSignatureDownloadedPrograms_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:307"/>
                                          <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:395"/>
                                    </check>
                              </Rule>
                              <Rule id="DoNotAllowResettingIESettings_LocalComputer" selected="false" weight="10.0">
                                    <title>Do Not Allow Resetting Internet Explorer Settings - Local Computer</title>
                                    <description>This policy setting prevents users from using the Reset Internet Explorer Settings feature. Reset Internet Explorer Settings will allow the users to reset all settings changed since install, delete browsing history and disable add-ons that are not preapproved.</description>
                                    <reference>
                                          <dc:type>GPO</dc:type>
                                          <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page</dc:source>
                                    </reference>
                                    <requires idref="CM-5"/>
                                    <ident system="http://cce.mitre.org">CCE-4171-5</ident>
                                    <ident system="cce.mitre.org/version/4">CCE-42</ident>
                                    <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                          <check-export value-id="DoNotAllowResettingIESettings_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:384"/>
                                          <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:583"/>
                                    </check>
                              </Rule>
                        </Group>
                        <Group id="security-page-policy">
                              <title>Security Page Policy</title>
                              <description>Security Page - Local Computer</description>
                              <Value id="include_all_network_paths_local_computer_var" type="number" operator="equals">
                                    <title>include_all_network_paths_local_computer_var</title>
                                    <description>include_all_network_paths_local_computer_var</description>
                                    <value>0</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Rule id="include_all_network_paths_local_computer" selected="false" weight="10.0">
                                    <title>Intranet Sites: Include all network paths (UNCs) - Local Computer</title>
                                    <description>This policy setting controls whether URLs representing UNCs are mapped into the local Intranet security zone. If you enable this policy setting, all network paths are mapped into the Intranet Zone.</description>
                                    <reference>
                                          <dc:type>GPO</dc:type>
                                          <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page</dc:source>
                                    </reference>
                                    <requires idref="AC-4"/>
                                    <ident system="http://cce.mitre.org">CCE-4175-6</ident>
                                    <ident system="cce.mitre.org/version/4">CCE-876</ident>
                                    <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                          <check-export value-id="include_all_network_paths_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:522"/>
                                          <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:559"/>
                                    </check>
                              </Rule>
                              <Rule id="site_to_zone_assignment_list_local_computer" selected="false" weight="10.0">
                                    <title>Site to Zone Assignment List</title>
                                    <description>Computer-wide, rather than per-user, assignment of sites to zones for Internet Explorer should be enabled or disabled as appropriate.</description>
                                    <reference>
                                          <dc:type>GPO</dc:type>
                                          <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page</dc:source>
                                    </reference>
                                    <requires idref="AC-4"/>
                                    <ident system="http://cce.mitre.org">CCE-4763-9</ident>
                                    <ident system="cce.mitre.org/version/4">CCE-1005</ident>
                                    <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                          <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:9998"/>
                                    </check>
                              </Rule>
                              <Group id="internet_zone_local_computer">
                                    <title>Internet Zone - Local Computer</title>
                                    <description>Internet Zone - Local Computer</description>
                                    <Value id="access_data_sources_across_domains_internet_zone_local_computer_var" type="number" operator="equals">
                                          <title>access_data_sources_across_domains_internet_zone_local_computer_var</title>
                                          <description>access_data_sources_across_domains_internet_zone_local_computer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="allow_cut_copy_paste_operations_from_clipboard_via_script_internet_zone_local_computer_var" type="number" operator="equals">
                                          <title>allow_cut_copy_paste_operations_from_clipboard_via_script_internet_zone_local_computer_var</title>
                                          <description>allow_cut_copy_paste_operations_from_clipboard_via_script_internet_zone_local_computer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="AllowDragDropOrCopyPasteFiles_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>AllowDragDropOrCopyPasteFiles_InternetZone_LocalComputer_var</title>
                                          <description>AllowDragDropOrCopyPasteFiles_InternetZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="AllowFontDownloads_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>AllowFontDownloads_InternetZone_LocalComputer_var</title>
                                          <description>AllowFontDownloads_InternetZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="AllowInstallationOfDesktopItems_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>AllowInstallationOfDesktopItems_InternetZone_LocalComputer_var</title>
                                          <description>AllowInstallationOfDesktopItems_InternetZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_InternetZone_LocalComputer_var</title>
                                          <description>AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_InternetZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="allow_scriptlets_internet_zone_local_computer_var" type="number" operator="equals">
                                          <title>allow_scriptlets_internet_zone_local_computer_var</title>
                                          <description>allow_scriptlets_internet_zone_local_computer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="allow_status_bar_updates_via_script_internet_zone_local_computer_var" type="number" operator="equals">
                                          <title>allow_status_bar_updates_via_script_internet_zone_local_computer_var</title>
                                          <description>allow_status_bar_updates_via_script_internet_zone_local_computer_var</description>
                                          <!-- 
                                                NOTE: May want to remove these variable values. 
                                                This check now checks if the key does not exist or it has the specified value. 
                                          -->
                                          <value>0</value>
                                          <value selector="FDCC">0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="AutomaticPromptingFileDownloads_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>AutomaticPromptingFileDownloads_InternetZone_LocalComputer_var</title>
                                          <description>AutomaticPromptingFileDownloads_InternetZone_LocalComputer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="download_signed_activex_controls_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>download_signed_activex_controls_InternetZone_LocalComputer_var</title>
                                          <description>download_signed_activex_controls_InternetZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="DownloadUnsignedActiveXControls_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>DownloadUnsignedActiveXControls_InternetZone_LocalComputer_var</title>
                                          <description>DownloadUnsignedActiveXControls_InternetZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="InitializeScriptActiveXControlsNotMarkedAsSafe_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>InitializeScriptActiveXControlsNotMarkedAsSafe_InternetZone_LocalComputer_var</title>
                                          <description>InitializeScriptActiveXControlsNotMarkedAsSafe_InternetZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="java_permissions_internet_zone_local_computer_var" type="number" operator="equals">
                                          <title>java_permissions_internet_zone_local_computer_var</title>
                                          <description>java_permissions_internet_zone_local_computer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:disable-java">0</value>
                                          <value selector="enabled:high-safety">65536</value>
                                          <value selector="enabled:medium-safety">131072</value>
                                          <value selector="enabled:low-safety">196608</value>
                                          <value selector="enabled:custom">8388608</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="LaunchingApplicationsAndFilesInIFRAME_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>LaunchingApplicationsAndFilesInIFRAME_InternetZone_LocalComputer_var</title>
                                          <description>LaunchingApplicationsAndFilesInIFRAME_InternetZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="LogonOptions_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>LogonOptions_InternetZone_LocalComputer_var</title>
                                          <description>LogonOptions_InternetZone_LocalComputer_var</description>
                                          <value>65536</value>
                                          <value selector="enabled:automatic_logon_with_current_user_name_and_password">0</value>
                                          <value selector="enabled:prompt_for_user_name_and_password">65536</value>
                                          <value selector="enabled:automatic_logon_only_in_intranet_zone">131072</value>
                                          <value selector="enabled:anonymous_logon">196608</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="LooseXAMLFiles_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>LooseXAMLFiles_InternetZone_LocalComputer_var</title>
                                          <description>LooseXAMLFiles_InternetZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="navigate_sub_frames_across_different_domains_Internet_zone_local_computer_var" type="number" operator="equals">
                                          <title>navigate_sub_frames_across_different_domains_Internet_zone_local_computer_var</title>
                                          <description>navigate_sub_frames_across_different_domains_Internet_zone_local_computer_var</description>
                                          <!-- 
                                                NOTE: May want to remove these variable values. 
                                                This check now checks if the key does not exist or it has the specified value. 
                                          -->
                                          <value>0</value>
                                          <value selector="FDCC">0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="OpenFilesBasedOnContent_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>OpenFilesBasedOnContent_InternetZone_LocalComputer_var</title>
                                          <description>OpenFilesBasedOnContent_InternetZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="SoftwareChannelPermissions_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>SoftwareChannelPermissions_InternetZone_LocalComputer_var</title>
                                          <description>SoftwareChannelPermissions_InternetZone_LocalComputer_var</description>
                                          <value>65536</value>
                                          <value selector="enabled:high_safety">65536</value>
                                          <value selector="enabled:medium_safety">131072</value>
                                          <value selector="enabled:low_safety">196608</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="TurnOffFirstRunOptIn_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>TurnOffFirstRunOptIn_InternetZone_LocalComputer_var</title>
                                          <description>todo - description needed</description>
                                          <value>0</value>
                                          <value selector="enabled:disable">0</value>
                                          <value selector="enabled:enable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="TurnOnProtectedMode_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>TurnOnProtectedMode_InternetZone_LocalComputer_var</title>
                                          <description>todo - description needed</description>
                                          <value>0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="UsePop-upBlocker_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>UsePop-upBlocker_InternetZone_LocalComputer_var</title>
                                          <description>UsePop-upBlocker_InternetZone_LocalComputer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="UserdataPersistence_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>UserdataPersistence_InternetZone_LocalComputer_var</title>
                                          <description>UserdataPersistence_InternetZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="WebBrowserApplications_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>WebBrowserApplications_InternetZone_LocalComputer_var</title>
                                          <description>WebBrowserApplications_InternetZone_LocalComputer_var</description>
                                          <!-- 
                                                NOTE: May want to remove these variable values. 
                                                This check now checks if the key does not exist or it has the specified value. 
                                          -->
                                          <value>0</value>
                                          <value selector="FDCC">0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_InternetZone_LocalComputer_var" type="number" operator="equals">
                                          <title>WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_InternetZone_LocalComputer_var</title>
                                          <description>WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_InternetZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Rule id="access_data_sources_across_domains_internet_zone_local_computer" selected="false" weight="10.0">
                                          <title>Access Data Sources Across Domains - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="AC-4"/>
                                          <ident system="http://cce.mitre.org">CCE-3853-9</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-47</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="access_data_sources_across_domains_internet_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:749"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:674"/>
                                          </check>
                                    </Rule>
                                    <Rule id="allow_cut_copy_paste_operations_from_clipboard_via_script_internet_zone_local_computer" selected="false" weight="10.0">
                                          <title>Allow cut, copy or paste operations from the clipboard via script - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether scripts can perform a clipboard operation (for example, cut, copy, and paste) in a specified region. If you enable this policy setting, a script can perform a clipboard operation.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="SI-3"/>
                                          <ident system="http://cce.mitre.org">CCE-4109-5</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-49</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="allow_cut_copy_paste_operations_from_clipboard_via_script_internet_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:314"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:506"/>
                                          </check>
                                    </Rule>
                                    <Rule id="AllowDragDropOrCopyPasteFiles_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Allow drag and drop or copy and paste files - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether users can drag files or copy and paste files from a source within the zone. If you enable this policy setting, users can drag files or copy and paste files from this zone automatically.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="SI-3"/>
                                          <ident system="http://cce.mitre.org">CCE-3998-2</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-685</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="AllowDragDropOrCopyPasteFiles_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:521"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1083"/>
                                          </check>
                                    </Rule>
                                    <Rule id="AllowFontDownloads_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Allow Font Downloads - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether pages of the zone may download HTML fonts. If you enable this policy setting, HTML fonts can be downloaded automatically.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="SI-3"/>
                                          <ident system="http://cce.mitre.org">CCE-3888-5</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-491</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="AllowFontDownloads_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:697"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:524"/>
                                          </check>
                                    </Rule>
                                    <Rule id="AllowInstallationOfDesktopItems_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Allow installation of desktop items - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether users can install Active Desktop items from this zone. The settings for this option are: If you enable this policy setting, users can install desktop items from this zone automatically.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="SI-3"/>
                                          <ident system="http://cce.mitre.org">CCE-3906-5</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-355</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="AllowInstallationOfDesktopItems_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:149"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:223"/>
                                          </check>
                                    </Rule>
                                    <Rule id="AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Allow script-initiated windows without size or position constraints - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage restrictions on script-initiated pop-up windows and windows that include the title and status bars. If you enable this policy setting, Windows Restrictions security will not apply in this zone.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <requires idref="SI-3"/>
                                          <ident system="http://cce.mitre.org">CCE-4099-8</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-280</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:795"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:589"/>
                                          </check>
                                    </Rule>
                                    <Rule id="allow_scriptlets_internet_zone_local_computer" selected="false" weight="10.0">
                                          <title>Allow Scriptlets - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether scriptlets can be allowed. If you enable this policy setting, users will be able to run scriptlets. If you disable this policy setting, users will not be able to run scriptlets.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <requires idref="SI-3"/>
                                          <ident system="http://cce.mitre.org">CCE-3601-2</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-439</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="allow_scriptlets_internet_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:621"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1043"/>
                                          </check>
                                    </Rule>
                                    <Rule id="allow_status_bar_updates_via_script_internet_zone_local_computer" selected="false" weight="10.0">
                                          <title>Allow status bar updates via script - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether script is allowed to update the status bar within the zone. If you enable this policy setting, script is allowed to update the status bar.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-8"/>
                                          <requires idref="SI-3"/>
                                          <ident system="http://cce.mitre.org">CCE-3249-0</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-914</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="allow_status_bar_updates_via_script_internet_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:119"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:226"/>
                                          </check>
                                    </Rule>
                                    <Rule id="AutomaticPromptingFileDownloads_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Automatic prompting for file downloads - Internet Zone - Local Computer</title>
                                          <description>This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="SI-3"/>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4139-2</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-16</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="AutomaticPromptingFileDownloads_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:763"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1113"/>
                                          </check>
                                    </Rule>
                                    <Rule id="download_signed_activex_controls_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Download signed ActiveX controls - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether users may download signed ActiveX controls from a page in the zone. If you enable this policy, users can download signed controls without user intervention.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="SI-3"/>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-3927-1</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-1013</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="download_signed_activex_controls_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:803"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1199"/>
                                          </check>
                                    </Rule>
                                    <Rule id="DownloadUnsignedActiveXControls_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Download unsigned ActiveX controls - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether users may download unsigned ActiveX controls from the zone. Such code is potentially harmful, especially when coming from an untrusted zone.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="SI-3"/>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-3945-3</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-176</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="DownloadUnsignedActiveXControls_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:969"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:391"/>
                                          </check>
                                    </Rule>
                                    <Rule id="InitializeScriptActiveXControlsNotMarkedAsSafe_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Initialize and script ActiveX controls not marked as safe - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage ActiveX controls not marked as safe. If you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4068-3</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-586</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="InitializeScriptActiveXControlsNotMarkedAsSafe_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:568"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1040"/>
                                          </check>
                                    </Rule>
                                    <Rule id="java_permissions_internet_zone_local_computer" selected="false" weight="10.0">
                                          <title>Java permissions - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage permissions for Java applets. If you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-3963-6</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-132</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="java_permissions_internet_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:340"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1174"/>
                                          </check>
                                    </Rule>
                                    <Rule id="LaunchingApplicationsAndFilesInIFRAME_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Launching applications and files in an IFRAME - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether applications may be run and files may be downloaded from an IFRAME reference in the HTML of the pages in this zone.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="SI-3"/>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4104-6</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-689</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="LaunchingApplicationsAndFilesInIFRAME_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:593"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:611"/>
                                          </check>
                                    </Rule>
                                    <Rule id="LogonOptions_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Logon Options - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage settings for logon options. If you enable this policy setting, you can choose from the following logon options.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <requires idref="IA-2"/>
                                          <ident system="http://cce.mitre.org">CCE-3623-6</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-720</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="LogonOptions_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:723"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:691"/>
                                          </check>
                                    </Rule>
                                    <Rule id="LooseXAMLFiles_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Loose or un-compiled XAML files - Internet Zone - Local Computer</title>
                                          <description>These are eXtensible Application Markup Language (XAML) files. XAML is an XML-based declarative markup language commonly used for creating rich user interfaces and graphics that leverage the Windows Presentation Foundation.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <ident system="http://cce.mitre.org">CCE-3751-5</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-126</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="LooseXAMLFiles_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:916"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:240"/>
                                          </check>
                                    </Rule>
                                    <Rule id="navigate_sub_frames_across_different_domains_Internet_zone_local_computer" selected="false" weight="10.0">
                                          <title>Navigate sub-frames across different domains - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage the opening of sub-frames and access of applications across different domains. If you enable this policy setting, users can open sub-frames from other domains and access applications from other domains.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <ident system="http://cce.mitre.org">CCE-4143-4</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-245</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="navigate_sub_frames_across_different_domains_Internet_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:909"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:612"/>
                                          </check>
                                    </Rule>
                                    <Rule id="OpenFilesBasedOnContent_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Open files based on content, not file extension - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage MIME sniffing for file promotion from one type to another based on a MIME sniff. A MIME sniff is the recognition by Internet Explorer of the file type based on a bit signature.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <ident system="http://cce.mitre.org">CCE-4161-6</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-910</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="OpenFilesBasedOnContent_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:299"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:953"/>
                                          </check>
                                    </Rule>
                                    <Rule id="SoftwareChannelPermissions_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Software channel permissions - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage software channel permissions. If you enable this policy setting, you can choose the following options from the drop-down box.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-5"/>
                                          <ident system="http://cce.mitre.org">CCE-3553-5</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-359</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="SoftwareChannelPermissions_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:681"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:302"/>
                                          </check>
                                    </Rule>
                                    <Rule id="TurnOffFirstRunOptIn_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Turn Off First-Run Opt-In - Internet Zone - Local Computer</title>
                                          <description>Turn Off First-Run Opt-In</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <ident system="http://cce.mitre.org">CCE-3378-7</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-863</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="TurnOffFirstRunOptIn_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:105"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1119"/>
                                          </check>
                                    </Rule>
                                    <Rule id="TurnOnProtectedMode_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Turn On Protected Mode - Internet Zone - Local Computer</title>
                                          <description>The "Turn on Protected Mode" setting should be configured correctly for the Internet Zone.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <ident system="http://cce.mitre.org">CCE-4643-3</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-281</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="TurnOnProtectedMode_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:10599"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:111999"/>
                                          </check>
                                    </Rule>
                                    <Rule id="UsePop-upBlocker_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Use Pop-up Blocker - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether unwanted pop-up windows appear. Pop-up windows that are opened when the end user clicks a link are not blocked. If you enable this policy setting, most unwanted pop-up windows are prevented from appearing.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="SI-8"/>
                                          <ident system="http://cce.mitre.org">CCE-3619-4</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-1002</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="UsePop-upBlocker_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:404"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1179"/>
                                          </check>
                                    </Rule>
                                    <Rule id="UserdataPersistence_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Userdata Persistence - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-4"/>
                                          <ident system="http://cce.mitre.org">CCE-3914-9</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-425</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="UserdataPersistence_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:277"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1108"/>
                                          </check>
                                    </Rule>
                                    <Rule id="WebBrowserApplications_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Web Browser Applications - Internet Zone - Local Computer</title>
                                          <description>These are browser-hosted, ClickOnce-deployed applications built using WinFX. These applications execute in a security sandbox and harness the power of the Windows Presentation Foundation platform for the Web.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <ident system="http://cce.mitre.org">CCE-4131-9</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-286</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="WebBrowserApplications_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:8"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:242"/>
                                          </check>
                                    </Rule>
                                    <Rule id="WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_InternetZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Web sites in less privileged Web content zones can navigate into this zone - Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether Web sites from less privileged zones, such as Restricted Sites, can navigate into this zone.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="AC-4"/>
                                          <ident system="http://cce.mitre.org">CCE-3570-9</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-724</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_InternetZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:95"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:265"/>
                                          </check>
                                    </Rule>
                              </Group>
                              <Group id="intranet_zone_local_computer">
                                    <title>Intranet Zone - Local Computer</title>
                                    <description>Intranet Zone - Local Computer</description>
                                    <Value id="display_mixed_content_intranet_zone_local_computer_var" type="number" operator="equals">
                                          <title>display_mixed_content_intranet_zone_local_computer_var</title>
                                          <description>display_mixed_content_intranet_zone_local_computer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="java_permissions_intranet_zone_local_computer_var" type="number" operator="equals">
                                          <title>java_permissions_intranet_zone_local_computer_var</title>
                                          <description>java_permissions_intranet_zone_local_computer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:disable-java">0</value>
                                          <value selector="enabled:high-safety">65536</value>
                                          <value selector="enabled:medium-safety">131072</value>
                                          <value selector="enabled:low-safety">196608</value>
                                          <value selector="enabled:custom">8388608</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Rule id="display_mixed_content_intranet_zone_local_computer" selected="false" weight="10.0">
                                          <title>Display Mixed Content - Intranet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether users can display nonsecure items and manage whether users receive a security information message to display pages containing both secure and nonsecure items.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone</dc:source>
                                          </reference>
                                          <requires idref="AC-3"/>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-3989-1</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-288</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="display_mixed_content_intranet_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:415"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1166"/>
                                          </check>
                                    </Rule>
                                    <Rule id="java_permissions_intranet_zone_local_computer" selected="false" weight="10.0">
                                          <title>Java permissions - Intranet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage permissions for Java applets. If you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4652-4</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-218</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="java_permissions_intranet_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:23"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1883"/>
                                          </check>
                                    </Rule>
                              </Group>
                              <Group id="local_machine_zone_local_computer">
                                    <title>Local Machine Zone - Local Computer</title>
                                    <description>Local Machine Zone - Local Computer</description>
                                    <Value id="display_mixed_content-local_machine_zone_local_computer_var" type="number" operator="equals">
                                          <title>display_mixed_content-local_machine_zone_local_computer_var</title>
                                          <description>display_mixed_content-local_machine_zone_local_computer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="java_permissions_local_machine_zone_local_computer_var" type="number" operator="equals">
                                          <title>java_permissions_local_machine_zone_local_computer_var</title>
                                          <description>java_permissions_local_machine_zone_local_computer_var</description>
                                          <value>0</value>
                                          <value selector="FDCC">0</value>
                                          <value selector="enabled:disable-java">0</value>
                                          <value selector="enabled:high-safety">65536</value>
                                          <value selector="enabled:medium-safety">131072</value>
                                          <value selector="enabled:low-safety">196608</value>
                                          <value selector="enabled:custom">8388608</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Rule id="display_mixed_content-local_machine_zone_local_computer" selected="false" weight="10.0">
                                          <title>Display Mixed Content - Local Machine Zone - Local Compute</title>
                                          <description>This policy setting allows you to manage whether users can display nonsecure items and manage whether users receive a security information message to display pages containing both secure and nonsecure items.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone</dc:source>
                                          </reference>
                                          <requires idref="AC-3"/>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4138-4</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-473</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="display_mixed_content-local_machine_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:12"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:383"/>
                                          </check>
                                    </Rule>
                                    <Rule id="java_permissions_local_machine_zone_local_computer" selected="false" weight="10.0">
                                          <title>Java permissions - Local Machine Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage permissions for Java applets. If you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-3891-9</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-138</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="java_permissions_local_machine_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:767"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1422"/>
                                          </check>
                                    </Rule>
                              </Group>
                              <Group id="locked_down_internet_zone_local_computer">
                                    <title>Locked Down Internet Zone - Local Computer</title>
                                    <description>Locked Down Internet Zone - Local Computer</description>
                                    <Value id="display_mixed_content_locked_down_internet_zone_local_computer_var" type="number" operator="equals">
                                          <title>display_mixed_content_locked_down_internet_zone_local_computer_var</title>
                                          <description>todo - description needed</description>
                                          <value>0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="download_signed_activex_controls_locked_down_internet_zone_local_computer_var" type="number" operator="equals">
                                          <title>download_signed_activex_controls_locked_down_internet_zone_local_computer_var</title>
                                          <description>todo - description needed</description>
                                          <value>0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="java_permissions_locked_down_internet_zone_local_computer_var" type="number" operator="equals">
                                          <title>java_permissions_locked_down_internet_zone_local_computer_var</title>
                                          <description>todo - description needed</description>
                                          <value>0</value>
                                          <value selector="enabled:disable-java">0</value>
                                          <value selector="enabled:high-safety">65536</value>
                                          <value selector="enabled:medium-safety">131072</value>
                                          <value selector="enabled:low-safety">196608</value>
                                          <value selector="enabled:custom">8388608</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Rule id="display_mixed_content_locked_down_internet_zone_local_computer" selected="false" weight="10.0">
                                          <title>Display Mixed Content - Locked Down Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether users can display nonsecure items and manage whether users receive a security information message to display pages containing both secure and nonsecure items.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="AC-3"/>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-3984-2</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-878</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="display_mixed_content_locked_down_internet_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:982"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:245"/>
                                          </check>
                                    </Rule>
                                    <Rule id="download_signed_activex_controls_locked_down_internet_zone_local_computer" selected="false" weight="10.0">
                                          <title>Download Signed ActiveX Controls - Locked Down Internet Zone - Local Computer</title>
                                          <description>The "Download signed ActiveX controls" setting should be configured correctly for the Locked-Down Internet Zone.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4793-6</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-308</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="download_signed_activex_controls_locked_down_internet_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:98299"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:24599"/>
                                          </check>
                                    </Rule>
                                    <Rule id="java_permissions_locked_down_internet_zone_local_computer" selected="false" weight="10.0">
                                          <title>Java permissions - Locked Down Internet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage permissions for Java applets. If you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4692-0</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-781</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="java_permissions_locked_down_internet_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:576"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1419"/>
                                          </check>
                                    </Rule>
                              </Group>
                              <Group id="locked_down_intranet_zone_local_computer">
                                    <title>Locked Down Intranet Zone - Local Computer</title>
                                    <description>LockedDown Intranet Zone - Local Computer</description>
                                    <Value id="display_mixed_content-LockedDownintranet_zone_local_computer_var" type="number" operator="equals">
                                          <title>display_mixed_content-LockedDownintranet_zone_local_computer_var</title>
                                          <description>display_mixed_content-LockedDownintranet_zone_local_computer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="java_permissions_LockedDownintranet_zone_local_computer_var" type="number" operator="equals">
                                          <title>java_permissions_LockedDownintranet_zone_local_computer_var</title>
                                          <description>java_permissions_LockedDownintranet_zone_local_computer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:disable-java">0</value>
                                          <value selector="enabled:high-safety">65536</value>
                                          <value selector="enabled:medium-safety">131072</value>
                                          <value selector="enabled:low-safety">196608</value>
                                          <value selector="enabled:custom">8388608</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Rule id="display_mixed_content-LockedDownintranet_zone_local_computer" selected="false" weight="10.0">
                                          <title>Display Mixed Content - Locked Down Intranet Zone - Local Compute</title>
                                          <description>This policy setting allows you to manage whether users can display nonsecure items and manage whether users receive a security information message to display pages containing both secure and nonsecure items.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone</dc:source>
                                          </reference>
                                          <requires idref="AC-3"/>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4121-0</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-552</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="display_mixed_content-LockedDownintranet_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:542"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:247"/>
                                          </check>
                                    </Rule>
                                    <Rule id="java_permissions_LockedDownintranet_zone_local_computer" selected="false" weight="10.0">
                                          <title>Java permissions - Locked Down Intranet Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage permissions for Java applets. If you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-3754-9</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-320</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="java_permissions_LockedDownintranet_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:960"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:2039"/>
                                          </check>
                                    </Rule>
                              </Group>
                              <Group id="locked_down_local_machine_zone_local_computer">
                                    <title>Locked Down Local Machine Zone - Local Computer</title>
                                    <description>Locked Down Local Machine Zone - Local Computer</description>
                                    <Value id="display_mixed_content-LockedDownlocal_machine_zone_local_computer_var" type="number" operator="equals">
                                          <title>display_mixed_content-LockedDownlocal_machine_zone_local_computer_var</title>
                                          <description>display_mixed_content-LockedDownlocal_machine_zone_local_computer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="java_permissions_LockedDownlocal_machine_zone_local_computer_var" type="number" operator="equals">
                                          <title>java_permissions_LockedDownlocal_machine_zone_local_computer_var</title>
                                          <description>java_permissions_LockedDownlocal_machine_zone_local_computer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:disable-java">0</value>
                                          <value selector="enabled:high-safety">65536</value>
                                          <value selector="enabled:medium-safety">131072</value>
                                          <value selector="enabled:low-safety">196608</value>
                                          <value selector="enabled:custom">8388608</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Rule id="display_mixed_content-LockedDownlocal_machine_zone_local_computer" selected="false" weight="10.0">
                                          <title>Display Mixed Content - Locked Down Local Machine Zone - Local Compute</title>
                                          <description>This policy setting allows you to manage whether users can display nonsecure items and manage whether users receive a security information message to display pages containing both secure and nonsecure items.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone</dc:source>
                                          </reference>
                                          <requires idref="AC-3"/>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4028-7</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-239</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="display_mixed_content-LockedDownlocal_machine_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:609"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:418"/>
                                          </check>
                                    </Rule>
                                    <Rule id="java_permissions_LockedDownlocal_machine_zone_local_computer" selected="false" weight="10.0">
                                          <title>Java permissions - Locked Down Local Machine - Local Computer</title>
                                          <description>This policy setting allows you to manage permissions for Java applets. If you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4160-8</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-1045</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="java_permissions_LockedDownlocal_machine_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:361"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1986"/>
                                          </check>
                                    </Rule>
                              </Group>
                              <Group id="locked_down_restricted_sites_zone_local_computer">
                                    <title>Locked Down Restricted Sites Zone - Local Compute - Local Computer</title>
                                    <description>Locked Down Restricted Sites Zone - Local Computer</description>
                                    <Value id="display_mixed_content-LockedDownRestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>display_mixed_content-LockedDownRestrictedSitesZone_LocalComputer_var</title>
                                          <description>display_mixed_content-LockedDownRestrictedSitesZone_LocalComputer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="java_permissions_LockedDownRestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>java_permissions_LockedDownRestrictedSitesZone_LocalComputer_var</title>
                                          <description>java_permissions_LockedDownRestrictedSitesZone_LocalComputer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:disable-java">0</value>
                                          <value selector="enabled:high-safety">65536</value>
                                          <value selector="enabled:medium-safety">131072</value>
                                          <value selector="enabled:low-safety">196608</value>
                                          <value selector="enabled:custom">8388608</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Rule id="display_mixed_content-LockedDownRestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Display Mixed Content - Locked Down Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether users can display nonsecure items and manage whether users receive a security information message to display pages containing both secure and nonsecure items.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="AC-3"/>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-3264-9</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-30</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="display_mixed_content-LockedDownRestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:187"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:314"/>
                                          </check>
                                    </Rule>
                                    <Rule id="java_permissions_LockedDownRestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Java permissions - Locked Down Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage permissions for Java applets. If you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-3902-4</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-1088</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="java_permissions_LockedDownRestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:493"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1753"/>
                                          </check>
                                    </Rule>
                              </Group>
                              <Group id="locked_down_trusted_sites_zone_local_computer">
                                    <title>Locked Down Trusted Sites Zone - Local Computer - Local Compute</title>
                                    <description>Locked Down Trusted Sites Zone - Local Computer</description>
                                    <Value id="AllowStatusBarUpdatesViaScript_LockedDowntrusted_sites_zone_local_computer_var" type="number" operator="equals">
                                          <title>AllowStatusBarUpdatesViaScript_LockedDowntrusted_sites_zone_local_computer_var</title>
                                          <description>todo - description needed</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="display_mixed_content_LockedDowntrusted_sites_zone_local_computer_var" type="number" operator="equals">
                                          <title>display_mixed_content_LockedDowntrusted_sites_zone_local_computer_var</title>
                                          <description>display_mixed_content_LockedDowntrusted_sites_zone_local_computer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="java_permissions_LockedDowntrusted_sites_zone_local_computer_var" type="number" operator="equals">
                                          <title>java_permissions_LockedDowntrusted_sites_zone_local_computer_var</title>
                                          <description>java_permissions_LockedDowntrusted_sites_zone_local_computer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:disable-java">0</value>
                                          <value selector="enabled:high-safety">65536</value>
                                          <value selector="enabled:medium-safety">131072</value>
                                          <value selector="enabled:low-safety">196608</value>
                                          <value selector="enabled:custom">8388608</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Rule id="AllowStatusBarUpdatesViaScript_LockedDowntrusted_sites_zone_local_computer" selected="false" weight="10.0">
                                          <title>Allow Status Bar Updates Via Script - Locked Down Trusted Sites Zone - Local Computer</title>
                                          <description>The "Allow status bar updates via script" setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4546-8</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-1147</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="AllowStatusBarUpdatesViaScript_LockedDowntrusted_sites_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:38899"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:118399"/>
                                          </check>
                                    </Rule>
                                    <Rule id="display_mixed_content_LockedDowntrusted_sites_zone_local_computer" selected="false" weight="10.0">
                                          <title>Display Mixed Content - Locked Down Trusted Sites Zone - LocalComputer</title>
                                          <description>This policy setting allows you to manage whether users can display nonsecure items and manage whether users receive a security information message to display pages containing both secure and nonsecure items.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="AC-3"/>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4232-5</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-666</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="display_mixed_content_LockedDowntrusted_sites_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:388"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1183"/>
                                          </check>
                                    </Rule>
                                    <Rule id="java_permissions_LockedDowntrusted_sites_zone_local_computer" selected="false" weight="10.0">
                                          <title>Java permissions - Locked Down Trusted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage permissions for Java applets. If you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4564-1</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-140</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="java_permissions_LockedDowntrusted_sites_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:758"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1699"/>
                                          </check>
                                    </Rule>
                              </Group>
                              <Group id="restricted_sites_zone_local_computer">
                                    <title>Restricted Sites Zone - Local Computer</title>
                                    <description>Restricted Sites Zone - Local Computer</description>
                                    <Value id="AccessDataSourcesAcrossDomains_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>AccessDataSourcesAcrossDomains_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>AccessDataSourcesAcrossDomains_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="AllowActiveScripting_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>AllowActiveScripting_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>AllowActiveScripting_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="AllowBinaryAndScriptBehaviors_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>AllowBinaryAndScriptBehaviors_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>AllowBinaryAndScriptBehaviors_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="AllowCutCopyPasteOperationsFromClipboardViaScript_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>AllowCutCopyPasteOperationsFromClipboardViaScript_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>AllowCutCopyPasteOperationsFromClipboardViaScript_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="AllowDragDropOrCopyPasteFiles_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>AllowDragDropOrCopyPasteFiles_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>AllowDragDropOrCopyPasteFiles_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="AllowFileDownloads_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>AllowFileDownloads_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>AllowFileDownloads_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="AllowFontDownloads_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>AllowFontDownloads_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>AllowFontDownloads_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="AllowInstallationOfDesktopItems_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>AllowInstallationOfDesktopItems_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>AllowInstallationOfDesktopItems_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="AllowMETAREFRESH_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>AllowMETAREFRESH_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>AllowMETAREFRESH_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="AllowStatusBarUpdatesViaScript_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>AllowStatusBarUpdatesViaScript_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>AllowStatusBarUpdatesViaScript_RestrictedSitesZone_LocalComputer_var</description>
                                          <!-- 
                                                NOTE: May want to remove these variable values. 
                                                This check now checks if the key does not exist or it has the specified value. 
                                          -->
                                          <value>0</value>
                                          <value selector="FDCC">0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="AutomaticPromptingFileDownloads_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>AutomaticPromptingFileDownloads_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>AutomaticPromptingFileDownloads_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="download_signed_activex_controls_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>download_signed_activex_controls_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>download_signed_activex_controls_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="DownloadUnsignedActiveXControls_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>DownloadUnsignedActiveXControls_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>DownloadUnsignedActiveXControls_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="InitializeScriptActiveXControlsNotMarkedAsSafe_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>InitializeScriptActiveXControlsNotMarkedAsSafe_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>InitializeScriptActiveXControlsNotMarkedAsSafe_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="java_permissions_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>java_permissions_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>java_permissions_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:disable-java">0</value>
                                          <value selector="enabled:high-safety">65536</value>
                                          <value selector="enabled:medium-safety">131072</value>
                                          <value selector="enabled:low-safety">196608</value>
                                          <value selector="enabled:custom">8388608</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="LaunchingApplicationsAndFilesInIFRAME_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>LaunchingApplicationsAndFilesInIFRAME_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>LaunchingApplicationsAndFilesInIFRAME_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="LogonOptions_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>LogonOptions_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>LogonOptions_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>196608</value>
                                          <value selector="enabled:automatic_logon_with_current_user_name_and_password">0</value>
                                          <value selector="enabled:prompt_for_user_name_and_password">65536</value>
                                          <value selector="enabled:automatic_logon_only_in_intranet_zone">131072</value>
                                          <value selector="enabled:anonymous_logon">196608</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="LooseXAMLFiles_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>LooseXAMLFiles_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>LooseXAMLFiles_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="NavigateSub-framesAcrossDifferentDomains_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>NavigateSub-framesAcrossDifferentDomains_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>NavigateSub-framesAcrossDifferentDomains_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="OpenFilesBasedOnContent_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>OpenFilesBasedOnContent_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>OpenFilesBasedOnContent_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="RunNETFrameworkReliantComponentsNotSignedWithAuthenticode_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>RunNETFrameworkReliantComponentsNotSignedWithAuthenticode_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>RunNETFrameworkReliantComponentsNotSignedWithAuthenticode_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="RunNETFrameworkReliantComponentsSignedWithAuthenticode_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>RunNETFrameworkReliantComponentsSignedWithAuthenticode_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>RunNETFrameworkReliantComponentsSignedWithAuthenticode_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="RunActiveXControlsAndPlugins_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>RunActiveXControlsAndPlugins_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>RunActiveXControlsAndPlugins_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="ScriptActiveXControlsMarkedSafeForScripting_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>ScriptActiveXControlsMarkedSafeForScripting_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>ScriptActiveXControlsMarkedSafeForScripting_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="ScriptingOfJavaApplets_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>ScriptingOfJavaApplets_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>ScriptingOfJavaApplets_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="SoftwareChannelPermissions_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>SoftwareChannelPermissions_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>SoftwareChannelPermissions_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>65536</value>
                                          <value selector="enabled:high_safety">65536</value>
                                          <value selector="enabled:medium_safety">131072</value>
                                          <value selector="enabled:low_safety">196608</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="TurnOffFirstRunOptIn_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>TurnOffFirstRunOptIn_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>TurnOffFirstRunOptIn_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:disable">0</value>
                                          <value selector="enabled:enable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="TurnOnProtectedMode_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>TurnOnProtectedMode_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>todo - description needed</description>
                                          <value>0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="UsePop-upBlocker_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>UsePop-upBlocker_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>UsePop-upBlocker_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="UserdataPersistence_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>UserdataPersistence_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>UserdataPersistence_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="WebBrowserApplications_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>WebBrowserApplications_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>WebBrowserApplications_RestrictedSitesZone_LocalComputer_var</description>
                                          <!-- 
                                                NOTE: May want to remove these variable values. 
                                                This check now checks if the key does not exist or it has the specified value. 
                                          -->
                                          <value>0</value>
                                          <value selector="FDCC">0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_RestrictedSitesZone_LocalComputer_var" type="number" operator="equals">
                                          <title>WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_RestrictedSitesZone_LocalComputer_var</title>
                                          <description>WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_RestrictedSitesZone_LocalComputer_var</description>
                                          <value>3</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Rule id="AccessDataSourcesAcrossDomains_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Access Data Sources Across Domains - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="AC-4"/>
                                          <ident system="http://cce.mitre.org">CCE-3905-7</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-636</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="AccessDataSourcesAcrossDomains_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:656"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:652"/>
                                          </check>
                                    </Rule>
                                    <Rule id="AllowActiveScripting_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Allow Active Scripting - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether script code on pages in the zone is run. If you enable this policy setting, script code on pages in the zone can run automatically.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <requires idref="SI-3"/>
                                          <ident system="http://cce.mitre.org">CCE-4050-1</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-292</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="AllowActiveScripting_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:356"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:293"/>
                                          </check>
                                    </Rule>
                                    <Rule id="AllowBinaryAndScriptBehaviors_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Allow Binary and Script Behaviors - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage dynamic binary and script behaviors: components that encapsulate specific functionality for HTML elements to which they were attached. If you enable this policy setting, binary and script behaviors are available.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <requires idref="SI-3"/>
                                          <ident system="http://cce.mitre.org">CCE-4196-2</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-178</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="AllowBinaryAndScriptBehaviors_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:453"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:365"/>
                                          </check>
                                    </Rule>
                                    <Rule id="AllowCutCopyPasteOperationsFromClipboardViaScript_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Allow cut, copy or paste operations from the clipboard via script - Restricted SitesZone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether scripts can perform a clipboard operation (for example, cut, copy, and paste) in a specified region. If you enable this policy setting, a script can perform a clipboard operation.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <ident system="http://cce.mitre.org">CCE-4013-9</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-1031</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="AllowCutCopyPasteOperationsFromClipboardViaScript_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:487"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:249"/>
                                          </check>
                                    </Rule>
                                    <Rule id="AllowDragDropOrCopyPasteFiles_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Allow drag and drop or copy and paste files - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether users can drag files or copy and paste files from a source within the zone. If you enable this policy setting, users can drag files or copy and paste files from this zone automatically.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SI-3"/>
                                          <ident system="http://cce.mitre.org">CCE-3337-3</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-41</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="AllowDragDropOrCopyPasteFiles_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:877"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:498"/>
                                          </check>
                                    </Rule>
                                    <Rule id="AllowFileDownloads_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Allow File Downloads - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether file downloads are permitted from the zone. This option is determined by the zone of the page with the link causing the download, not the zone from which the file is delivered.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SI-3"/>
                                          <ident system="http://cce.mitre.org">CCE-4150-9</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-970</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="AllowFileDownloads_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:100"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1184"/>
                                          </check>
                                    </Rule>
                                    <Rule id="AllowFontDownloads_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Allow Font Downloads - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether pages of the zone may download HTML fonts. If you enable this policy setting, HTML fonts can be downloaded automatically.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SI-3"/>
                                          <ident system="http://cce.mitre.org">CCE-4062-6</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-882</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="AllowFontDownloads_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:516"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1109"/>
                                          </check>
                                    </Rule>
                                    <Rule id="AllowInstallationOfDesktopItems_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Allow installation of desktop items - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether users can install Active Desktop items from this zone. The settings for this option are: If you enable this policy setting, users can install desktop items from this zone automatically.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <ident system="http://cce.mitre.org">CCE-4079-0</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-763</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="AllowInstallationOfDesktopItems_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:35"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:251"/>
                                          </check>
                                    </Rule>
                                    <Rule id="AllowMETAREFRESH_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Allow META REFRESH - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether a user's browser can be redirected to another Web page if the author of the Web page uses the Meta Refresh setting (tag) to redirect browsers to another Web page.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <ident system="http://cce.mitre.org">CCE-4084-0</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-680</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="AllowMETAREFRESH_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:582"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1218"/>
                                          </check>
                                    </Rule>
                                    <Rule id="AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Allow script-initiated windows without size or position constraints - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage restrictions on script-initiated pop-up windows and windows that include the title and status bars. If you enable this policy setting, Windows Restrictions security will not apply in this zone.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <requires idref="SI-3"/>
                                          <ident system="http://cce.mitre.org">CCE-4119-4</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-208</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:393"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1234"/>
                                          </check>
                                    </Rule>
                                    <Rule id="AllowStatusBarUpdatesViaScript_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Allow status bar updates via script - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether script is allowed to update the status bar within the zone. If you enable this policy setting, script is allowed to update the status bar.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-8"/>
                                          <requires idref="SI-3"/>
                                          <ident system="http://cce.mitre.org">CCE-4031-1</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-129</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="AllowStatusBarUpdatesViaScript_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:555"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:378"/>
                                          </check>
                                    </Rule>
                                    <Rule id="AutomaticPromptingFileDownloads_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Automatic prompting for file downloads - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SI-3"/>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4053-5</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-175</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="AutomaticPromptingFileDownloads_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:559"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:252"/>
                                          </check>
                                    </Rule>
                                    <Rule id="download_signed_activex_controls_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Download signed ActiveX controls - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether users may download signed ActiveX controls from a page in the zone. If you enable this policy, users can download signed controls without user intervention.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SI-3"/>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4057-6</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-52</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="download_signed_activex_controls_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:294"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1019"/>
                                          </check>
                                    </Rule>
                                    <Rule id="DownloadUnsignedActiveXControls_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Download unsigned ActiveX controls - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether users may download unsigned ActiveX controls from the zone. Such code is potentially harmful, especially when coming from an untrusted zone.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <ident system="http://cce.mitre.org">CCE-3564-2</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-1012</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="DownloadUnsignedActiveXControls_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:973"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:949"/>
                                          </check>
                                    </Rule>
                                    <Rule id="InitializeScriptActiveXControlsNotMarkedAsSafe_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Initialize and script ActiveX controls not marked as safe - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage ActiveX controls not marked as safe. If you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4101-2</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-26</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="InitializeScriptActiveXControlsNotMarkedAsSafe_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:148"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:273"/>
                                          </check>
                                    </Rule>
                                    <Rule id="java_permissions_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Java permissions - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage permissions for Java applets. If you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-3996-6</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-925</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="java_permissions_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:965"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:824"/>
                                          </check>
                                    </Rule>
                                    <Rule id="LaunchingApplicationsAndFilesInIFRAME_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Launching applications and files in an IFRAME - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether applications may be run and files may be downloaded from an IFRAME reference in the HTML of the pages in this zone.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SI-3"/>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4066-7</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-339</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="LaunchingApplicationsAndFilesInIFRAME_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:754"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:274"/>
                                          </check>
                                    </Rule>
                                    <Rule id="LogonOptions_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Logon Options - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage settings for logon options. If you enable this policy setting, you can choose from the following logon options.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <requires idref="IA-2"/>
                                          <ident system="http://cce.mitre.org">CCE-3696-2</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-128</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="LogonOptions_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:668"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:326"/>
                                          </check>
                                    </Rule>
                                    <Rule id="LooseXAMLFiles_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Loose or un-compiled XAML files - Restricted Sites Zone - Local Computer</title>
                                          <description>These are eXtensible Application Markup Language (XAML) files. XAML is an XML-based declarative markup language commonly used for creating rich user interfaces and graphics that leverage the Windows Presentation Foundation.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <ident system="http://cce.mitre.org">CCE-3590-7</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-639</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="LooseXAMLFiles_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:310"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:275"/>
                                          </check>
                                    </Rule>
                                    <Rule id="NavigateSub-framesAcrossDifferentDomains_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Navigate sub-frames across different domains - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage the opening of sub-frames and access of applications across different domains. If you enable this policy setting, users can open sub-frames from other domains and access applications from other domains.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <ident system="http://cce.mitre.org">CCE-4110-3</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-995</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="NavigateSub-framesAcrossDifferentDomains_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:41"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1229"/>
                                          </check>
                                    </Rule>
                                    <Rule id="OpenFilesBasedOnContent_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Open files based on content, not file extension - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage MIME sniffing for file promotion from one type to another based on a MIME sniff. A MIME sniff is the recognition by Internet Explorer of the file type based on a bit signature.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <ident system="http://cce.mitre.org">CCE-4132-7</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-409</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="OpenFilesBasedOnContent_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:406"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:706"/>
                                          </check>
                                    </Rule>
                                    <Rule id="RunNETFrameworkReliantComponentsNotSignedWithAuthenticode_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Run .NET Framework-reliant components not signed with Authenticode - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <ident system="http://cce.mitre.org">CCE-3400-9</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-678</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="RunNETFrameworkReliantComponentsNotSignedWithAuthenticode_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:562"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:329"/>
                                          </check>
                                    </Rule>
                                    <Rule id="RunNETFrameworkReliantComponentsSignedWithAuthenticode_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Run .NET Framework-reliant components signed with Authenticode - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether .NET Framework components that are signed with Authenticode can be executed from Internet Explorer.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <ident system="http://cce.mitre.org">CCE-4158-2</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-563</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="RunNETFrameworkReliantComponentsSignedWithAuthenticode_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:921"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:276"/>
                                          </check>
                                    </Rule>
                                    <Rule id="RunActiveXControlsAndPlugins_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Run ActiveX controls and plugins - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether ActiveX controls and plug-ins can be run on pages from the specified zone. If you enable this policy setting, controls and plug-ins can run without user intervention.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4163-2</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-841</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="RunActiveXControlsAndPlugins_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:380"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:571"/>
                                          </check>
                                    </Rule>
                                    <Rule id="ScriptActiveXControlsMarkedSafeForScripting_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Script ActiveX controls marked safe for scripting - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether an ActiveX control marked safe for scripting can interact with a script. If you enable this policy setting, script interaction can occur automatically without user intervention.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4202-8</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-973</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="ScriptActiveXControlsMarkedSafeForScripting_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:940"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:602"/>
                                          </check>
                                    </Rule>
                                    <Rule id="ScriptingOfJavaApplets_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Scripting of Java Applets - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether applets are exposed to scripts within the zone. If you enable this policy setting, scripts can access applets automatically without user intervention.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-3216-9</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-1000</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="ScriptingOfJavaApplets_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:780"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:280"/>
                                          </check>
                                    </Rule>
                                    <Rule id="SoftwareChannelPermissions_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Software channel permissions - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage software channel permissions. If you enable this policy setting, you can choose the following options from the drop-down box.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-5"/>
                                          <ident system="http://cce.mitre.org">CCE-3855-4</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-520</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="SoftwareChannelPermissions_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:474"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:290"/>
                                          </check>
                                    </Rule>
                                    <Rule id="TurnOffFirstRunOptIn_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Turn Off First-Run Opt-In - Restricted Sites Zone - Local Computer</title>
                                          <description>Turn Off First-Run Opt-In</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <ident system="http://cce.mitre.org">CCE-4153-3</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-200</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="TurnOffFirstRunOptIn_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:686"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:621"/>
                                          </check>
                                    </Rule>
                                    <Rule id="TurnOnProtectedMode_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Turn On Protected Mode - Restricted Sites Zone - Local Computer</title>
                                          <description>The "Turn on Protected Mode" setting should be configured correctly for the Restricted Sites Zone.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <ident system="http://cce.mitre.org">CCE-3909-9</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-1211</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="TurnOnProtectedMode_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:68699"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:62199"/>
                                          </check>
                                    </Rule>
                                    <Rule id="UsePop-upBlocker_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Use Pop-up Blocker - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether unwanted pop-up windows appear. Pop-up windows that are opened when the end user clicks a link are not blocked.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SI-8"/>
                                          <ident system="http://cce.mitre.org">CCE-4018-8</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-660</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="UsePop-upBlocker_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:980"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1100"/>
                                          </check>
                                    </Rule>
                                    <Rule id="UserdataPersistence_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Userdata Persistence - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-4"/>
                                          <ident system="http://cce.mitre.org">CCE-4040-2</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-28</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="UserdataPersistence_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:797"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:300"/>
                                          </check>
                                    </Rule>
                                    <Rule id="WebBrowserApplications_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Web Browser Applications - Restricted Sites Zone - Local Computer</title>
                                          <description>These are browser-hosted, ClickOnce-deployed applications built using WinFX. These applications execute in a security sandbox and harness the power of the Windows Presentation Foundation platform for the Web.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="CM-6"/>
                                          <ident system="http://cce.mitre.org">CCE-4052-7</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-51</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="WebBrowserApplications_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:164"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:580"/>
                                          </check>
                                    </Rule>
                                    <Rule id="WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_RestrictedSitesZone_LocalComputer" selected="false" weight="10.0">
                                          <title>Web sites in less privileged Web content zones can navigate into this zone - Restricted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether Web sites from less privileged zones, such as Restricted Sites, can navigate into this zone.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="AC-4"/>
                                          <ident system="http://cce.mitre.org">CCE-4215-0</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-698</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_RestrictedSitesZone_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:392"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1219"/>
                                          </check>
                                    </Rule>
                              </Group>
                              <Group id="trusted_sites_zone_local_computer">
                                    <title>Trusted Sites Zone - Local Computer - Local Compute</title>
                                    <description>Trusted Sites Zone - Local Computer</description>
                                    <Value id="display_mixed_content_trusted_sites_zone_local_computer_var" type="number" operator="equals">
                                          <title>display_mixed_content_trusted_sites_zone_local_computer_var</title>
                                          <description>display_mixed_content_trusted_sites_zone_local_computer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:enable">0</value>
                                          <value selector="enabled:prompt">1</value>
                                          <value selector="enabled:disable">3</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Value id="java_permissions_trusted_sites_zone_local_computer_var" type="number" operator="equals">
                                          <title>java_permissions_trusted_sites_zone_local_computer_var</title>
                                          <description>java_permissions_trusted_sites_zone_local_computer_var</description>
                                          <value>0</value>
                                          <value selector="enabled:disable-java">0</value>
                                          <value selector="enabled:high-safety">65536</value>
                                          <value selector="enabled:medium-safety">131072</value>
                                          <value selector="enabled:low-safety">196608</value>
                                          <value selector="enabled:custom">8388608</value>
                                          <!-- <value selector="disabled">?????</value> -->
                                    </Value>
                                    <Rule id="display_mixed_content_trusted_sites_zone_local_computer" selected="false" weight="10.0">
                                          <title>Display Mixed Content - Trusted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage whether users can display nonsecure items and manage whether users receive a security information message to display pages containing both secure and nonsecure items.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="AC-3"/>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4087-3</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-31</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="display_mixed_content_trusted_sites_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:109"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1153"/>
                                          </check>
                                    </Rule>
                                    <Rule id="java_permissions_trusted_sites_zone_local_computer" selected="false" weight="10.0">
                                          <title>Java permissions - Trusted Sites Zone - Local Computer</title>
                                          <description>This policy setting allows you to manage permissions for Java applets. If you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.</description>
                                          <reference>
                                                <dc:type>GPO</dc:type>
                                                <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone</dc:source>
                                          </reference>
                                          <requires idref="SC-18"/>
                                          <ident system="http://cce.mitre.org">CCE-4845-4</ident>
                                          <ident system="cce.mitre.org/version/4">CCE-675</ident>
                                          <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                                <check-export value-id="java_permissions_trusted_sites_zone_local_computer_var" export-name="oval:gov.nist.fdcc.ie7:var:926"/>
                                                <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1379"/>
                                          </check>
                                    </Rule>
                              </Group>
                        </Group>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--          Periodic Check For Updates Policy          -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="periodic_check_for_updates_policy">
                        <title>Periodic Check for Updates - Local Computer</title>
                        <description>Periodic Check for Updates to Internet Explorer and Internet Tools - Local Computer</description>
                        <Value id="TurnOffChangingURLDisplay_LocalComputer_var" type="string" operator="equals">
                              <title>TurnOffChangingURLDisplay_LocalComputer_var</title>
                              <description>TurnOffChangingURLDisplay_LocalComputer_var</description>
                              <!-- NOTE: OVAL Definition needs to check that the registry key exists with an empty string for a value. -->
                              <value/>
                              <value selector="enabled:"/>
                        </Value>
                        <Value id="TurnOffConfiguringUpdateCheckInterval_LocalComputer_var" type="number" operator="equals">
                              <title>TurnOffConfiguringUpdateCheckInterval_LocalComputer_var</title>
                              <description>TurnOffConfiguringUpdateCheckInterval_LocalComputer_var</description>
                              <value>30</value>
                              <value selector="30_days">30</value>
                        </Value>
                        <Rule id="TurnOffChangingURLDisplay_LocalComputer" selected="false" weight="10.0">
                              <title>Turn Off changing the URL to be displayed for checking updates to Internet Explorer and Internet Tools - Local Computer</title>
                              <description>This policy setting allows checking for updates for Internet Explorer from the specified URL, included by default in Internet Explorer.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Component Updates\Periodic check for updates to Internet Explorer and Internet Tools</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3204-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-946</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="TurnOffChangingURLDisplay_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:935"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:715"/>
                              </check>
                        </Rule>
                        <Rule id="TurnOffConfiguringUpdateCheckInterval_LocalComputer" selected="false" weight="10.0">
                              <title>Turn Off Configuring the Update Check Interval (In Days) - Local Computer</title>
                              <description>This setting specifies the update check interval. The default value is 30 days. If you enable this policy setting, the user will not be able to configure the update check interval. You have to specify the update check interval.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Component Updates\Periodic check for updates to Internet Explorer and Internet Tools</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4098-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-237</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="TurnOffConfiguringUpdateCheckInterval_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:147"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1187"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--                Security Features Policy                 -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="security-features-policy">
                        <title>Security Features Policy</title>
                        <description>todo - description needed</description>
                        <Value id="EnableNativeXMLHttpSupport_LocalComputer_var">
                              <title>EnableNativeXMLHttpSupport_LocalComputer_var</title>
                              <description>EnableNativeXMLHttpSupport_LocalComputer_var</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="EnableNativeXMLHttpSupport_LocalComputer" selected="false" weight="10.0">
                              <title>Enable Native XMLHttp Support - Local Computer</title>
                              <description>Enable Native XMLHttp Support - Local Computer</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features</dc:source>
                              </reference>
                              <requires idref="SC-18"/>
                              <ident system="http://cce.mitre.org">CCE-4259-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-528</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="EnableNativeXMLHttpSupport_LocalComputer_var" export-name="oval:gov.nist.fdcc.ie7:var:483"/>
                                    <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:338"/>
                              </check>
                        </Rule>
                        <Group id="ConsistentMimeHandling_LocalComputer">
                              <title>Consistent Mime Handling - Local Computer</title>
                              <description>Consistent Mime Handling - Local Computer</description>
                              <Value id="IEProcesses_ConsistentMimeHandling_LocalComputer_1_var" type="number" operator="equals">
                                    <title>IEProcesses_ConsistentMimeHandling_LocalComputer_1_var</title>
                                    <description>IEProcesses_ConsistentMimeHandling_LocalComputer_1_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Value id="IEProcesses_ConsistentMimeHandling_LocalComputer_2_var" type="number" operator="equals">
                                    <title>IEProcesses_ConsistentMimeHandling_LocalComputer_2_var</title>
                                    <description>IEProcesses_ConsistentMimeHandling_LocalComputer_2_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Value id="IEProcesses_ConsistentMimeHandling_LocalComputer_3_var" type="number" operator="equals">
                                    <title>IEProcesses_ConsistentMimeHandling_LocalComputer_3_var</title>
                                    <description>IEProcesses_ConsistentMimeHandling_LocalComputer_3_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Rule id="IEProcesses_ConsistentMimeHandling_LocalComputer" selected="false" weight="10.0">
                                    <title>Internet Explorer Processes - Consistent Mime Handling - Local Computer</title>
                                    <description>Internet Explorer uses Multipurpose Internet Mail Extensions (MIME) data to determine file handling procedures for files received through a Web server.</description>
                                    <reference>
                                          <dc:type>GPO</dc:type>
                                          <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Consistent Mime Handling</dc:source>
                                    </reference>
                                    <requires idref="CM-6"/>
                                    <ident system="http://cce.mitre.org">CCE-4047-7</ident>
                                    <ident system="cce.mitre.org/version/4">CCE-382</ident>
                                    <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                          <check-export value-id="IEProcesses_ConsistentMimeHandling_LocalComputer_1_var" export-name="oval:gov.nist.fdcc.ie7:var:455"/>
                                          <check-export value-id="IEProcesses_ConsistentMimeHandling_LocalComputer_2_var" export-name="oval:gov.nist.fdcc.ie7:var:308"/>
                                          <check-export value-id="IEProcesses_ConsistentMimeHandling_LocalComputer_3_var" export-name="oval:gov.nist.fdcc.ie7:var:902"/>
                                          <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:884"/>
                                    </check>
                              </Rule>
                        </Group>
                        <Group id="MimeSniffingSafetyFeature_LocalComputer">
                              <title>Mime Sniffing Safety Feature - Local Computer</title>
                              <description>Mime Sniffing Safety Feature - Local Computer</description>
                              <Value id="IEProcesses_MimeSniffingSafetyFeature_LocalComputer_1_var" type="number" operator="equals">
                                    <title>IEProcesses_MimeSniffingSafetyFeature_LocalComputer_1_var</title>
                                    <description>IEProcesses_MimeSniffingSafetyFeature_LocalComputer_1_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Value id="IEProcesses_MimeSniffingSafetyFeature_LocalComputer_2_var" type="number" operator="equals">
                                    <title>IEProcesses_MimeSniffingSafetyFeature_LocalComputer_2_var</title>
                                    <description>IEProcesses_MimeSniffingSafetyFeature_LocalComputer_2_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Value id="IEProcesses_MimeSniffingSafetyFeature_LocalComputer_3_var" type="number" operator="equals">
                                    <title>IEProcesses_MimeSniffingSafetyFeature_LocalComputer_3_var</title>
                                    <description>IEProcesses_MimeSniffingSafetyFeature_LocalComputer_3_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Rule id="IEProcesses_MimeSniffingSafetyFeature_LocalComputer" selected="false" weight="10.0">
                                    <title>Internet Explorer Processes - Mime Sniffing Safety Feature - Local Computer</title>
                                    <description>MIME sniffing is the process of examining the content of a MIME file to determine its context — whether it is a data file, an executable file, or some other type of file.</description>
                                    <reference>
                                          <dc:type>GPO</dc:type>
                                          <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Mime Sniffing Safety Feature</dc:source>
                                    </reference>
                                    <requires idref="CM-6"/>
                                    <ident system="http://cce.mitre.org">CCE-4149-1</ident>
                                    <ident system="cce.mitre.org/version/4">CCE-985</ident>
                                    <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                          <check-export value-id="IEProcesses_MimeSniffingSafetyFeature_LocalComputer_1_var" export-name="oval:gov.nist.fdcc.ie7:var:574"/>
                                          <check-export value-id="IEProcesses_MimeSniffingSafetyFeature_LocalComputer_2_var" export-name="oval:gov.nist.fdcc.ie7:var:527"/>
                                          <check-export value-id="IEProcesses_MimeSniffingSafetyFeature_LocalComputer_3_var" export-name="oval:gov.nist.fdcc.ie7:var:557"/>
                                          <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:317"/>
                                    </check>
                              </Rule>
                        </Group>
                        <Group id="MKProtocolSecurityRestriction_LocalComputer">
                              <title>MK Protocol Security Restriction - Local Computer</title>
                              <description>MK Protocol Security Restriction - Local Computer</description>
                              <Value id="IEProcesses_MKProtocolSecurityRestriction_LocalComputer_1_var" type="number" operator="equals">
                                    <title>IEProcesses_MKProtocolSecurityRestriction_LocalComputer_1_var</title>
                                    <description>IEProcesses_MKProtocolSecurityRestriction_LocalComputer_1_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Value id="IEProcesses_MKProtocolSecurityRestriction_LocalComputer_2_var" type="number" operator="equals">
                                    <title>IEProcesses_MKProtocolSecurityRestriction_LocalComputer_2_var</title>
                                    <description>IEProcesses_MKProtocolSecurityRestriction_LocalComputer_2_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Value id="IEProcesses_MKProtocolSecurityRestriction_LocalComputer_3_var" type="number" operator="equals">
                                    <title>IEProcesses_MKProtocolSecurityRestriction_LocalComputer_3_var</title>
                                    <description>IEProcesses_MKProtocolSecurityRestriction_LocalComputer_3_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Rule id="IEProcesses_MKProtocolSecurityRestriction_LocalComputer" selected="false" weight="10.0">
                                    <title>Internet Explorer Processes - MK Protocol Security Restriction - Local Computer</title>
                                    <description>The MK Protocol Security Restriction policy setting reduces attack surface area by blocking the seldom used MK protocol. Some older Web applications use the MK protocol to retrieve information from compressed files.</description>
                                    <reference>
                                          <dc:type>GPO</dc:type>
                                          <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\MK Protocol Security Restriction</dc:source>
                                    </reference>
                                    <requires idref="CM-6"/>
                                    <ident system="http://cce.mitre.org">CCE-3338-1</ident>
                                    <ident system="cce.mitre.org/version/4">CCE-591</ident>
                                    <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                          <check-export value-id="IEProcesses_MKProtocolSecurityRestriction_LocalComputer_1_var" export-name="oval:gov.nist.fdcc.ie7:var:988"/>
                                          <check-export value-id="IEProcesses_MKProtocolSecurityRestriction_LocalComputer_2_var" export-name="oval:gov.nist.fdcc.ie7:var:488"/>
                                          <check-export value-id="IEProcesses_MKProtocolSecurityRestriction_LocalComputer_3_var" export-name="oval:gov.nist.fdcc.ie7:var:275"/>
                                          <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:617"/>
                                    </check>
                              </Rule>
                        </Group>
                        <Group id="ProtectionFromZoneElevation_LocalComputer">
                              <title>Protection From Zone Elevation - Local Computer</title>
                              <description>Protection From Zone Elevation - Local Computer</description>
                              <Value id="IEProcesses_ProtectionFromZoneElevation_LocalComputer_1_var" type="number" operator="equals">
                                    <title>IEProcesses_ProtectionFromZoneElevation_LocalComputer_1_var</title>
                                    <description>IEProcesses_ProtectionFromZoneElevation_LocalComputer_1_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Value id="IEProcesses_ProtectionFromZoneElevation_LocalComputer_2_var" type="number" operator="equals">
                                    <title>IEProcesses_ProtectionFromZoneElevation_LocalComputer_2_var</title>
                                    <description>IEProcesses_ProtectionFromZoneElevation_LocalComputer_2_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Value id="IEProcesses_ProtectionFromZoneElevation_LocalComputer_3_var" type="number" operator="equals">
                                    <title>IEProcesses_ProtectionFromZoneElevation_LocalComputer_3_var</title>
                                    <description>IEProcesses_ProtectionFromZoneElevation_LocalComputer_3_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Rule id="IEProcesses_ProtectionFromZoneElevation_LocalComputer" selected="false" weight="10.0">
                                    <title>Internet Explorer Processes - Protection From Zone Elevation - Local Computer</title>
                                    <description>Internet Explorer places restrictions on each Web page it opens that are dependent upon the location of the Web page (such as Internet zone, Intranet zone, or Local Machine zone).</description>
                                    <reference>
                                          <dc:type>GPO</dc:type>
                                          <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Protection From Zone Elevation</dc:source>
                                    </reference>
                                    <requires idref="CM-6"/>
                                    <ident system="http://cce.mitre.org">CCE-4043-6</ident>
                                    <ident system="cce.mitre.org/version/4">CCE-347</ident>
                                    <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                          <check-export value-id="IEProcesses_ProtectionFromZoneElevation_LocalComputer_1_var" export-name="oval:gov.nist.fdcc.ie7:var:698"/>
                                          <check-export value-id="IEProcesses_ProtectionFromZoneElevation_LocalComputer_2_var" export-name="oval:gov.nist.fdcc.ie7:var:720"/>
                                          <check-export value-id="IEProcesses_ProtectionFromZoneElevation_LocalComputer_3_var" export-name="oval:gov.nist.fdcc.ie7:var:616"/>
                                          <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:620"/>
                                    </check>
                              </Rule>
                        </Group>
                        <Group id="RestrictActiveXInstall_LocalComputer">
                              <title>Restrict ActiveX Install - Local Computer</title>
                              <description>Restrict ActiveX Install - Local Computer</description>
                              <Value id="IEProcesses_RestrictActiveXInstall_LocalComputer_1_var" type="number" operator="equals">
                                    <title>IEProcesses_RestrictActiveXInstall_LocalComputer_1_var</title>
                                    <description>IEProcesses_RestrictActiveXInstall_LocalComputer_1_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Value id="IEProcesses_RestrictActiveXInstall_LocalComputer_2_var" type="number" operator="equals">
                                    <title>IEProcesses_RestrictActiveXInstall_LocalComputer_2_var</title>
                                    <description>IEProcesses_RestrictActiveXInstall_LocalComputer_2_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Value id="IEProcesses_RestrictActiveXInstall_LocalComputer_3_var" type="number" operator="equals">
                                    <title>IEProcesses_RestrictActiveXInstall_LocalComputer_3_var</title>
                                    <description>IEProcesses_RestrictActiveXInstall_LocalComputer_3_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Rule id="IEProcesses_RestrictActiveXInstall_LocalComputer" selected="false" weight="10.0">
                                    <title>Internet Explorer Processes - Restrict ActiveX Install - Local Computer</title>
                                    <description>The Restrict ActiveX Install\Internet Explorer Processes policy setting enables blocking of ActiveX control installation prompts for Internet Explorer processes.</description>
                                    <reference>
                                          <dc:type>GPO</dc:type>
                                          <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Restrict ActiveX Install</dc:source>
                                    </reference>
                                    <requires idref="CM-6"/>
                                    <ident system="http://cce.mitre.org">CCE-3924-8</ident>
                                    <ident system="cce.mitre.org/version/4">CCE-119</ident>
                                    <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                          <check-export value-id="IEProcesses_RestrictActiveXInstall_LocalComputer_1_var" export-name="oval:gov.nist.fdcc.ie7:var:478"/>
                                          <check-export value-id="IEProcesses_RestrictActiveXInstall_LocalComputer_2_var" export-name="oval:gov.nist.fdcc.ie7:var:586"/>
                                          <check-export value-id="IEProcesses_RestrictActiveXInstall_LocalComputer_3_var" export-name="oval:gov.nist.fdcc.ie7:var:930"/>
                                          <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:658"/>
                                    </check>
                              </Rule>
                        </Group>
                        <Group id="RestrictFileDownload_LocalComputer">
                              <title>Restrict File Download - Local Computer</title>
                              <description>Restrict File Download - Local Computer</description>
                              <Value id="IEProcesses_RestrictFileDownload_LocalComputer_1_var" type="number" operator="equals">
                                    <title>IEProcesses_RestrictFileDownload_LocalComputer_1_var</title>
                                    <description>IEProcesses_RestrictFileDownload_LocalComputer_1_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Value id="IEProcesses_RestrictFileDownload_LocalComputer_2_var" type="number" operator="equals">
                                    <title>IEProcesses_RestrictFileDownload_LocalComputer_2_var</title>
                                    <description>IEProcesses_RestrictFileDownload_LocalComputer_2_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Value id="IEProcesses_RestrictFileDownload_LocalComputer_3_var" type="number" operator="equals">
                                    <title>IEProcesses_RestrictFileDownload_LocalComputer_3_var</title>
                                    <description>IEProcesses_RestrictFileDownload_LocalComputer_3_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Rule id="IEProcesses_RestrictFileDownload_LocalComputer" selected="false" weight="10.0">
                                    <title>Internet Explorer Processes - Restrict File Download - Local Computer</title>
                                    <description>In certain circumstances, Web sites can initiate file download prompts without interaction from users. This technique can allow Web sites to put unauthorized files on users' hard drives if they click the wrong button and accept the download.</description>
                                    <reference>
                                          <dc:type>GPO</dc:type>
                                          <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Restrict File Download</dc:source>
                                    </reference>
                                    <requires idref="CM-6"/>
                                    <ident system="http://cce.mitre.org">CCE-4122-8</ident>
                                    <ident system="cce.mitre.org/version/4">CCE-668</ident>
                                    <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                          <check-export value-id="IEProcesses_RestrictFileDownload_LocalComputer_1_var" export-name="oval:gov.nist.fdcc.ie7:var:837"/>
                                          <check-export value-id="IEProcesses_RestrictFileDownload_LocalComputer_2_var" export-name="oval:gov.nist.fdcc.ie7:var:382"/>
                                          <check-export value-id="IEProcesses_RestrictFileDownload_LocalComputer_3_var" export-name="oval:gov.nist.fdcc.ie7:var:687"/>
                                          <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:320"/>
                                    </check>
                              </Rule>
                        </Group>
                        <Group id="ScriptedWindowSecurityRestrictions_LocalComputer">
                              <title>Scripted Window Security Restrictions - Local Computer</title>
                              <description>Scripted Window Security Restrictions - Local Computer</description>
                              <Value id="IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer_1_var" type="number" operator="equals">
                                    <title>IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer_1_var</title>
                                    <description>IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer_1_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Value id="IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer_2_var" type="number" operator="equals">
                                    <title>IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer_2_var</title>
                                    <description>IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer_2_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Value id="IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer_3_var" type="number" operator="equals">
                                    <title>IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer_3_var</title>
                                    <description>IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer_3_var</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Rule id="IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer" selected="false" weight="10.0">
                                    <title>Internet Explorer Processes - Scripted Window Security Restrictions - Local Computer</title>
                                    <description>Internet Explorer allows scripts to programmatically open, resize, and reposition various types of windows. Often, disreputable Web sites will resize windows to either hide other windows or force you to interact with a window that contains malicious code.</description>
                                    <reference>
                                          <dc:type>GPO</dc:type>
                                          <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Scripted Window Security Restrictions</dc:source>
                                    </reference>
                                    <requires idref="CM-6"/>
                                    <ident system="http://cce.mitre.org">CCE-4162-4</ident>
                                    <ident system="cce.mitre.org/version/4">CCE-827</ident>
                                    <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                          <check-export value-id="IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer_1_var" export-name="oval:gov.nist.fdcc.ie7:var:942"/>
                                          <check-export value-id="IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer_2_var" export-name="oval:gov.nist.fdcc.ie7:var:774"/>
                                          <check-export value-id="IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer_3_var" export-name="oval:gov.nist.fdcc.ie7:var:506"/>
                                          <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:465"/>
                                    </check>
                              </Rule>
                        </Group>
                        <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                        <!--                 RSS Feeds Settings                 -->
                        <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                        <Group id="rss_feeds_settings">
                              <title>Windows Components - RSS Feeds</title>
                              <description>RSS Feeds</description>
                              <Value id="Turn_off_downloading_enclosures_var" operator="equals" type="number">
                                    <title>Turn off downloading of enclosures</title>
                                    <description>Turn off downloading of enclosures</description>
                                    <value>1</value>
                                    <value selector="disabled">0</value>
                                    <value selector="enabled">1</value>
                              </Value>
                              <Rule id="Turn_off_downloading_enclosures" selected="false" weight="10.0">
                                    <title>Turn off downloading of enclosures</title>
                                    <description>Turn off downloading of enclosures</description>
                                    <reference>
                                          <dc:type>GPO</dc:type>
                                          <dc:source>Computer Configuration\Administrative Templates\Windows Components\RSS Feeds</dc:source>
                                    </reference>
                                    <requires idref="CM-6"/>
                                    <ident system="http://cce.mitre.org">CCE-4581-5</ident>
                                    <ident system="http://cce.mitre.org">CCE-3477-7</ident>
                                    <ident system="cce.mitre.org/version/4">CCE-767</ident>
                                    <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                          <check-export export-name="oval:gov.nist.fdcc.ie7:var:61101" value-id="Turn_off_downloading_enclosures_var"/>
                                          <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:6110"/>
                                    </check>
                              </Rule>
                        </Group>
                  </Group>
            </Group>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  Local User Policy                                                                         -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="local-user-policy">
                  <title>Local User Policy</title>
                  <description>todo - description needed</description>
                  <Value id="configure_outlook_express_local_user_var" type="number" operator="equals">
                        <title>configure_outlook_express_local_user_var</title>
                        <description>configure_outlook_express_local_user_var</description>
                        <value>0</value>
                        <value selector="disabled">0</value>
                        <value selector="enabled:block-attachments">1</value>
                  </Value>
                  <Value id="DisableAutoCompleteForForms_LocalUser_1_var" type="string" operator="equals">
                        <title>DisableAutoCompleteForForms_LocalUser_1_var</title>
                        <description>DisableAutoCompleteForForms_LocalUser_1_var</description>
                        <value>no</value>
                        <value selector="enabled">no</value>
                        <value selector="disabled">yes</value>
                  </Value>
                  <Value id="DisableAutoCompleteForForms_LocalUser_2_var" type="number" operator="equals">
                        <title>DisableAutoCompleteForForms_LocalUser_2_var</title>
                        <description>DisableAutoCompleteForForms_LocalUser_2_var</description>
                        <value>1</value>
                        <value selector="enabled">1</value>
                  </Value>
                  <Value id="DisableExternalBrandingOfIE_LocalUser_var" type="number" operator="equals">
                        <title>DisableExternalBrandingOfIE_LocalUser_var</title>
                        <description>DisableExternalBrandingOfIE_LocalUser_var</description>
                        <value>1</value>
                        <!-- <value selector="disabled">????</value> -->
                        <value selector="enabled">1</value>
                  </Value>
                  <Value id="DisableInternetConnectionWizard_LocalUser_var" type="number" operator="equals">
                        <title>DisableInternetConnectionWizard_LocalUser_var</title>
                        <description>DisableInternetConnectionWizard_LocalUser_var</description>
                        <value>1</value>
                        <!-- <value selector="disabled">????</value> -->
                        <value selector="enabled">1</value>
                  </Value>
                  <Value id="DisableResetWebSettingsFeature_LocalUser_var" type="number" operator="equals">
                        <title>DisableResetWebSettingsFeature_LocalUser_var</title>
                        <description>DisableResetWebSettingsFeature_LocalUser_var</description>
                        <value>1</value>
                        <!-- <value selector="disabled">????</value> -->
                        <value selector="enabled">1</value>
                  </Value>
                  <Value id="TurnOnAutoCompleteFeatureForUserNamesAndPasswords_LocalUser_1_var" type="string" operator="equals">
                        <title>TurnOnAutoCompleteFeatureForUserNamesAndPasswords_LocalUser_1_var</title>
                        <description>TurnOnAutoCompleteFeatureForUserNamesAndPasswords_LocalUser_1_var</description>
                        <value>no</value>
                        <value selector="disabled">no</value>
                        <value selector="enabled">yes</value>
                  </Value>
                  <Value id="TurnOnAutoCompleteFeatureForUserNamesAndPasswords_LocalUser_2_var" type="number" operator="equals">
                        <title>TurnOnAutoCompleteFeatureForUserNamesAndPasswords_LocalUser_2_var</title>
                        <description>TurnOnAutoCompleteFeatureForUserNamesAndPasswords_LocalUser_2_var</description>
                        <value>1</value>
                        <value selector="disabled">1</value>
                  </Value>
                  <Value id="TurnOffPageTransitions_LocalUser_var" type="number" operator="equals">
                        <title>TurnOffPageTransitions_LocalUser_var</title>
                        <description>TurnOffPageTransitions_LocalUser_var</description>
                        <value>0</value>
                        <value selector="enabled">0</value>
                        <value selector="disabled">1</value>
                  </Value>
                  <Value id="TurnOnInternetConnectionWizardAutoDetect_LocalUser_var" type="number" operator="equals">
                        <title>TurnOnInternetConnectionWizardAutoDetect_LocalUser_var</title>
                        <description>TurnOnInternetConnectionWizardAutoDetect_LocalUser_var</description>
                        <value>1</value>
                        <value selector="enabled">0</value>
                        <value selector="disabled">1</value>
                  </Value>
                  <Rule id="configure_outlook_express_local_user" selected="false" weight="10.0">
                        <title>Configure Outlook Express - Local User</title>
                        <description>The Configure Outlook Express setting allows administrators to enable and disable the ability for Microsoft Outlook Express users to save or open attachments that can potentially contain a virus.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>User Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <ident system="http://cce.mitre.org">CCE-3275-5</ident>
                        <ident system="cce.mitre.org/version/4">CCE-963</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export value-id="configure_outlook_express_local_user_var" export-name="oval:gov.nist.fdcc.ie7:var:518"/>
                              <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1238"/>
                        </check>
                  </Rule>
                  <Rule id="DisableAutoCompleteForForms_LocalUser" selected="false" weight="10.0">
                        <title>Disable AutoComplete for forms - Local User</title>
                        <description>This AutoComplete feature suggests possible matches when users are filling up forms. If you enable this setting, the user is not suggested matches when filling forms. The user cannot change it.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>User Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                        </reference>
                        <requires idref="CM-5"/>
                        <ident system="http://cce.mitre.org">CCE-4246-5</ident>
                        <ident system="cce.mitre.org/version/4">CCE-478</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export value-id="DisableAutoCompleteForForms_LocalUser_1_var" export-name="oval:gov.nist.fdcc.ie7:var:798"/>
                              <check-export value-id="DisableAutoCompleteForForms_LocalUser_2_var" export-name="oval:gov.nist.fdcc.ie7:var:956"/>
                              <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1516"/>
                        </check>
                  </Rule>
                  <Rule id="DisableExternalBrandingOfIE_LocalUser" selected="false" weight="10.0">
                        <title>Disable external branding of Internet Explorer - Local User</title>
                        <description>Prevents branding of Internet programs, such as customization of Internet Explorer and Outlook Express logos and title bars, by another party.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>User Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <ident system="http://cce.mitre.org">CCE-4237-4</ident>
                        <ident system="cce.mitre.org/version/4">CCE-1051</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export value-id="DisableExternalBrandingOfIE_LocalUser_var" export-name="oval:gov.nist.fdcc.ie7:var:848"/>
                              <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1384"/>
                        </check>
                  </Rule>
                  <Rule id="DisableInternetConnectionWizard_LocalUser" selected="false" weight="10.0">
                        <title>Disable Internet Connection wizard - Local User</title>
                        <description>Prevents users from running the Internet Connection Wizard.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>User Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <ident system="http://cce.mitre.org">CCE-3825-7</ident>
                        <ident system="cce.mitre.org/version/4">CCE-769</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export value-id="DisableInternetConnectionWizard_LocalUser_var" export-name="oval:gov.nist.fdcc.ie7:var:491"/>
                              <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1355"/>
                        </check>
                  </Rule>
                  <Rule id="DisableResetWebSettingsFeature_LocalUser" selected="false" weight="10.0">
                        <title>Disable the Reset Web Settings feature - Local User</title>
                        <description>Prevents users from restoring default settings for home and search pages. If you enable this policy, the Reset Web Settings button on the Programs tab in the Internet Options dialog box appears dimmed.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>User Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                        </reference>
                        <requires idref="CM-5"/>
                        <requires idref="CM-6"/>
                        <ident system="http://cce.mitre.org">CCE-4226-7</ident>
                        <ident system="cce.mitre.org/version/4">CCE-625</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export value-id="DisableResetWebSettingsFeature_LocalUser_var" export-name="oval:gov.nist.fdcc.ie7:var:141"/>
                              <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1437"/>
                        </check>
                  </Rule>
                  <Rule id="TurnOnAutoCompleteFeatureForUserNamesAndPasswords_LocalUser" selected="false" weight="10.0">
                        <title>Turn on the auto-complete feature for user names and passwords on forms - Local User</title>
                        <description>This AutoComplete feature can remember and suggest User names and passwords on Forms. If you enable this setting, the user cannot change "User name and passwords on forms" or "prompt me to save passwords".</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>User Configuration\Administrative Templates\Windows Components\Internet Explorer</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="IA-5"/>
                        <ident system="http://cce.mitre.org">CCE-3647-5</ident>
                        <ident system="cce.mitre.org/version/4">CCE-721</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export value-id="TurnOnAutoCompleteFeatureForUserNamesAndPasswords_LocalUser_1_var" export-name="oval:gov.nist.fdcc.ie7:var:372"/>
                              <check-export value-id="TurnOnAutoCompleteFeatureForUserNamesAndPasswords_LocalUser_2_var" export-name="oval:gov.nist.fdcc.ie7:var:879"/>
                              <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:645"/>
                        </check>
                  </Rule>
                  <Rule id="TurnOffPageTransitions_LocalUser" selected="false" weight="10.0">
                        <title>Turn off page transitions - Local User</title>
                        <description>This policy setting specifies if, as you move from one Web page to another, Internet Explorer fades out of the page you are leaving and fades into the page to which you are going. If you enable this policy setting, page transitions will be turned off.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Advanced Settings\Browsing</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <ident system="http://cce.mitre.org">CCE-4056-8</ident>
                        <ident system="cce.mitre.org/version/4">CCE-71</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export value-id="TurnOffPageTransitions_LocalUser_var" export-name="oval:gov.nist.fdcc.ie7:var:600"/>
                              <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:1206"/>
                        </check>
                  </Rule>
                  <Rule id="TurnOnInternetConnectionWizardAutoDetect_LocalUser" selected="false" weight="10.0">
                        <title>Turn on the Internet Connection Wizard Auto Detect - Local User</title>
                        <description>This policy setting determines if the Internet Connection Wizard was completed. If it was not completed, it launches the Internet Connection Wizard. </description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Advanced Settings\Internet Connection Wizard Settings</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <ident system="http://cce.mitre.org">CCE-4036-0</ident>
                        <ident system="cce.mitre.org/version/4">CCE-258</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export value-id="TurnOnInternetConnectionWizardAutoDetect_LocalUser_var" export-name="oval:gov.nist.fdcc.ie7:var:101"/>
                              <check-content-ref href="fdcc-ie7-oval.xml" name="oval:gov.nist.fdcc.ie7:def:604"/>
                        </check>
                  </Rule>
            </Group>
      </Group>
      <!-- **************************************************************************************************** -->
      <!-- ***  4 - Security Patches                                                                        *** -->
      <!-- **************************************************************************************************** -->
      <Group id="security_patches">
            <title>Security Patches</title>
            <description>Securing a given computer has become increasingly important. As such, it is essential to keep a host up to current patch levels to eliminate known vulnerabilities and weaknesses. In conjunction with antivirus software and a personal firewall, patching goes a long way to securing a host against outside attacks and exploitation. Microsoft provides two mechanisms for distributing security updates: Automatic Updates and Microsoft Update. In smaller environments, either method may be sufficient for keeping systems current with patches. Other environments typically have a software change management control process or a patch management program that tests patches before deploying them; distribution may then occur through local Windows Update Services (WUS) or Windows Server Update Services (WSUS) servers, which provide approved security patches for use by the Automatic Updates feature.</description>
            <Rule id="security_patches_up_to_date" selected="false" weight="10.0">
                  <title>Security Patches Up-To-Date</title>
                  <description>Keep systems up to current patch levels to eliminate known vulnerabilities and weaknesses.</description>
                  <requires idref="CM-6"/>
                  <requires idref="SI-2"/>
                  <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                        <check-content-ref href="http://nvd.nist.gov/scap/content/fdcc-ie7-patches.xml"/>
                        <check-content-ref href="fdcc-ie7-patches.xml"/>
                  </check>
            </Rule>
      </Group>
      <!-- ==================================================================================================== -->
      <!-- ==================================================================================================== -->
      <!-- ==================================================================================================== -->
</Benchmark>
