Microsoft Excel 2007
Pick two releases to diff their requirements.
Open a previous version of this STIG.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO104 - Excel
- Vuln IDs
-
- V-17173
- Rule IDs
-
- SV-18567r1_rule
Checks: C-17847r1_chk
If Office 2007 PRE SP2: The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2007 system (Machine) -> Security Settings -> IE Security “Disable user name and password” will be set to “Enabled” and ‘excel.exe’ is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE Criteria: If the value excel.exe is REG_DWORD = 1, this is not a finding. If Office 2007 SP2: The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2007 system (Machine) -> Security Settings -> IE Security “Disable user name and password” will be set to “Enabled” and ‘excel.exe’ is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE Criteria: If the value excel.exe is REG_DWORD = 1, this is not a finding.
Fix: F-16954r1_fix
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2007 system (Machine) -> Security Settings -> IE Security “Disable user name and password” will be set to “Enabled” and ‘excel.exe’ is checked.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO111 - Excel
- Vuln IDs
-
- V-17174
- Rule IDs
-
- SV-18185r1_rule
Checks: C-17863r1_chk
If Office 2007 PRE SP2: The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2007 system (Machine) -> Security Settings -> IE Security “Bind to Object” will be set to “Enabled” and ‘excel.exe’ is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT Criteria: If the value excel.exe is REG_DWORD = 1, this is not a finding. If Office 2007 SP2: The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2007 system (Machine) -> Security Settings -> IE Security “Bind to Object” will be set to “Enabled” and ‘excel.exe’ is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT Criteria: If the value excel.exe is REG_DWORD = 1, this is not a finding.
Fix: F-16961r1_fix
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2007 system (Machine) -> Security Settings -> IE Security “Bind to Object” will be set to “Enabled” and ‘excel.exe’ is checked. Note: In Office SP2 adm use, filtering in GPEDIT.MSC should have deselected any checks in "Only show configured policy settings" box, and "Only show policy settings that can be fully managed" box, in order to view the hive within the GP Console for policy use.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO117 - Excel
- Vuln IDs
-
- V-17175
- Rule IDs
-
- SV-18200r1_rule
Checks: C-17882r1_chk
If Office 2007 PRE SP2: The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2007 system (Machine) -> Security Settings -> IE Security “Saved from URL” will be set to “Enabled” and ‘excel.exe’ is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK Criteria: If the value excel.exe is REG_DWORD = 1, this is not a finding. If Office 2007 SP2: The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2007 system (Machine) -> Security Settings -> IE Security “Saved from URL” will be set to “Enabled” and ‘excel.exe’ is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK Criteria: If the value excel.exe is REG_DWORD = 1, this is not a finding.
Fix: F-17047r1_fix
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2007 system (Machine) -> Security Settings -> IE Security “Saved from URL” will be set to “Enabled” and ‘excel.exe’ is checked. Note: In Office SP2 adm use, filtering in GPEDIT.MSC should have deselected any checks in "Only show configured policy settings" box, and "Only show policy settings that can be fully managed" box, in order to view the hive within the GP Console for policy use.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO123 - Excel
- Vuln IDs
-
- V-17183
- Rule IDs
-
- SV-18207r1_rule
Checks: C-17890r1_chk
If Office 2007 PRE SP2: The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2007 system (Machine) -> Security Settings -> IE Security “Navigate URL” will be set to “Enabled” and ‘excel.exe’ is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL Criteria: If the value excel.exe is REG_DWORD = 1, this is not a finding. If Office 2007 SP2: The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2007 system (Machine) -> Security Settings -> IE Security “Navigate URL” will be set to “Enabled” and ‘excel.exe’ is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL Criteria: If the value excel.exe is REG_DWORD = 1, this is not a finding.
Fix: F-17053r1_fix
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2007 system (Machine) -> Security Settings -> IE Security “Navigate URL” will be set to “Enabled” and ‘excel.exe’ is checked. Note: In Office SP2 adm use, filtering in GPEDIT.MSC should have deselected any checks in "Only show configured policy settings" box, and "Only show policy settings that can be fully managed" box, in order to view the hive within the GP Console for policy use.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO129 - Excel
- Vuln IDs
-
- V-17184
- Rule IDs
-
- SV-18210r1_rule
Checks: C-17893r1_chk
If Office 2007 PRE SP2: The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2007 system (Machine) -> Security Settings -> IE Security “Block popups” will be set to “Enabled” and ‘excel.exe’ is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT Criteria: If the value excel.exe is REG_DWORD = 1, this is not a finding. If Office 2007 SP2: The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2007 system (Machine) -> Security Settings -> IE Security “Block popups” will be set to “Enabled” and ‘excel.exe’ is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT Criteria: If the value excel.exe is REG_DWORD = 1, this is not a finding.
Fix: F-17055r1_fix
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2007 system (Machine) -> Security Settings -> IE Security “Block popups” will be set to “Enabled” and ‘excel.exe’ is checked. Note: In Office SP2 adm use, filtering in GPEDIT.MSC should have deselected any checks in "Only show configured policy settings" box, and "Only show policy settings that can be fully managed" box, in order to view the hive within the GP Console for policy use.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO131 - Excel
- Vuln IDs
-
- V-17187
- Rule IDs
-
- SV-18220r1_rule
Checks: C-17913r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center “Disable Trust Bar Notification for unsigned application add-ins” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security Criteria: If the value NoTBPromptUnsignedAddin is REG_DWORD = 1, this is not a finding.
Fix: F-17080r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center “Disable Trust Bar Notification for unsigned application add-ins” will be set to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO210 - Excel
- Vuln IDs
-
- V-17322
- Rule IDs
-
- SV-18558r1_rule
Checks: C-18827r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2007 system -> Office 2007 Converters “Block opening of pre-release versions of file formats new to Excel 2007 through the Compatibility Pack for the 2007 Office system and Excel 2007 Converter” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security\FileOpenBlock Criteria: If the value Excel12BetaFilesFromConverters is REG_DWORD = 1, this is not a finding.
Fix: F-17425r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2007 system -> Office 2007 Converters “Block opening of pre-release versions of file formats new to Excel 2007 through the Compatibility Pack for the 2007 Office system and Excel 2007 Converter” will be set to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO133 - Excel
- Vuln IDs
-
- V-17471
- Rule IDs
-
- SV-18529r1_rule
Checks: C-18818r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center -> Trusted Locations “Disable all trusted locations” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security\Trusted Locations Criteria: If the value AllLocationsDisabled is REG_DWORD = 1, this is not a finding.
Fix: F-17410r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center -> Trusted Locations “Disable all trusted locations” will be set to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO142 - Excel
- Vuln IDs
-
- V-17473
- Rule IDs
-
- SV-18534r1_rule
Checks: C-18821r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security “Determine whether to force encrypted macros to be scanned in Microsoft Excel Open XML workbooks” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security Criteria: If the value ExcelBypassEncryptedMacroScan is REG_DWORD = 0, this is not a finding.
Fix: F-17413r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security “Determine whether to force encrypted macros to be scanned in Microsoft Excel Open XML workbooks” will be set to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO155 - Excel
- Vuln IDs
-
- V-17503
- Rule IDs
-
- SV-18573r1_rule
Checks: C-18830r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Block file formats -> Save “Block saving of Open XML file types” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security\FileSaveBlock Criteria: If the value OpenXmlFiles is REG_DWORD = 0, this is not a finding.
Fix: F-17428r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Block file formats -> Save “Block saving of Open XML file types” will be set to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO153 - Excel
- Vuln IDs
-
- V-17518
- Rule IDs
-
- SV-18589r1_rule
Checks: C-18833r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Block file formats -> Open “Block opening of files created by pre-release versions of Excel 2007” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security\FileOpenBlock Criteria: If the value Excel12BetaFiles is REG_DWORD = 1, this is not a finding.
Fix: F-17433r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Block file formats -> Open “Block opening of files created by pre-release versions of Excel 2007” will be set to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO154 - Excel
- Vuln IDs
-
- V-17519
- Rule IDs
-
- SV-18595r1_rule
Checks: C-18838r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Block file formats -> Open “Block opening of Open XML file types” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security\FileOpenBlock Criteria: If the value OpenXmlFiles is REG_DWORD = 0, this is not a finding.
Fix: F-17438r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Block file formats -> Open “Block opening of Open XML file types” will be set to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO134 - Excel
- Vuln IDs
-
- V-17520
- Rule IDs
-
- SV-18598r1_rule
Checks: C-18840r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center -> Trusted Locations “Allow Trusted Locations not on the computer” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security\Trusted Locations Criteria: If the value AllowNetworkLocations is REG_DWORD = 0, this is not a finding.
Fix: F-17440r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center -> Trusted Locations “Allow Trusted Locations not on the computer” will be set to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO139 - Excel
- Vuln IDs
-
- V-17521
- Rule IDs
-
- SV-18606r1_rule
Checks: C-18847r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Save "save excel files as" will be set to "Enabled (Excel 97-2003 Workbook(*.xls)" or "Enabled (Excel Workbook *.xlsx"). Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Options Criteria: If the value DefaultFormat is REG_DWORD = 38 (hex) or 56 (Decimal) for Excel 97-2003 or If the value DefaultFormat is REG_DWORD = 33 (hex) or 51 (Decimal) for 2007 .xlsx , this is not a finding.
Fix: F-17447r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Save "save excel files as" will be set to "Enabled (Excel 97-2003 Workbook(*.xls)" or "Enabled (Excel Workbook *.xlsx").
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO146 - Excel
- Vuln IDs
-
- V-17522
- Rule IDs
-
- SV-18610r1_rule
Checks: C-18850r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center “Trust access to Visual Basic Project” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security Criteria: If the value AccessVBOM is REG_DWORD = 0, this is not a finding.
Fix: F-17450r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center “Trust access to Visual Basic Project” will be set to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO304 - Excel
- Vuln IDs
-
- V-17545
- Rule IDs
-
- SV-18638r1_rule
Checks: C-18855r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center “VBA macro warning settings” will be set to “Enabled (Trust Bar warning for all macros)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security Criteria: If the value VBAWarnings is REG_DWORD = 2, this is not a finding.
Fix: F-17466r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center “VBA macro warning settings” will be set to “Enabled (Trust Bar warning for all macros)”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO143 - Excel
- Vuln IDs
-
- V-17621
- Rule IDs
-
- SV-18762r1_rule
Checks: C-18915r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security “Force file extension to match file type” will be set to “Enabled (Allow different, but warn)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security Criteria: If the value ExtensionHardening is REG_DWORD = 1, this is not a finding.
Fix: F-17533r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security “Force file extension to match file type” will be set to “Enabled (Allow different, but warn)”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO138 - Excel
- Vuln IDs
-
- V-17650
- Rule IDs
-
- SV-18797r3_rule
Checks: C-18922r6_chk
If Office 2007 PRE SP2: The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Proofing -> Autocorrect Options “Internet and network paths as hyperlinks” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Options Criteria: If the value AutoHyperlink exists, this is a finding. If Office 2007 SP2 : The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Proofing -> Autocorrect Options “Internet and network paths as hyperlinks” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Options Criteria: If the value AutoHyperlink is REG_DWORD=0, this is not a finding.
Fix: F-17549r3_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Proofing -> Autocorrect Options “Internet and network paths as hyperlinks” will be set to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO140 - Excel
- Vuln IDs
-
- V-17652
- Rule IDs
-
- SV-18800r1_rule
Checks: C-18923r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Save “Disable AutoRepublish” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Options Criteria: If the value DisableAutoRepublish is REG_DWORD = 1, this is not a finding.
Fix: F-17550r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Save “Disable AutoRepublish” will be set to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO150 - Excel
- Vuln IDs
-
- V-17732
- Rule IDs
-
- SV-18908r1_rule
Checks: C-18998r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Advanced “Ask to update automatic links” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Options\BinaryOptions Criteria: If the value fUpdateExt_78_1 is REG_DWORD = 0, this is not a finding.
Fix: F-17632r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Advanced “Ask to update automatic links” will be set to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO141 - Excel
- Vuln IDs
-
- V-17744
- Rule IDs
-
- SV-18928r1_rule
Checks: C-19006r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Save “AutoRepublish Warning Alert” will be set to “Enabled (Always show the alert before publishing)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Options Criteria: If the value DisableAutoRepublishWarning is REG_DWORD = 0, this is not a finding.
Fix: F-17643r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Save “AutoRepublish Warning Alert” will be set to “Enabled (Always show the alert before publishing)”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO152 - Excel
- Vuln IDs
-
- V-17751
- Rule IDs
-
- SV-18941r1_rule
Checks: C-19013r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Advanced -> Web Options -> General “Load pictures from Web pages not created in Excel” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Internet Criteria: If the value DoNotLoadPictures is REG_DWORD = 1, this is not a finding.
Fix: F-17650r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Advanced -> Web Options -> General “Load pictures from Web pages not created in Excel” will be set to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO151 -Excel
- Vuln IDs
-
- V-17796
- Rule IDs
-
- SV-19021r1_rule
Checks: C-19048r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Advanced -> Web Options -> General “Save any additional data necessary to maintain formulas” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Internet Criteria: If the value DoNotSaveHiddenData is REG_DWORD = 1, this is not a finding.
Fix: F-17696r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Advanced -> Web Options -> General “Save any additional data necessary to maintain formulas” will be set to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO145 - Excel
- Vuln IDs
-
- V-17804
- Rule IDs
-
- SV-19034r1_rule
Checks: C-19060r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center “Store macro in Personal Macro Workbook by default” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Options\BinaryOptions Criteria: If the value fGlobalSheet_37_1 is REG_DWORD = 1, this is not a finding.
Fix: F-17705r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center “Store macro in Personal Macro Workbook by default” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Options\BinaryOptions Criteria: If the value fGlobalSheet_37_1 is REG_DWORD = 1, this is not a finding.