Select any two versions of this STIG to compare the individual requirements
Select any old version/release of this STIG to view the previous requirements
Validate the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Disable user name and password” is set to “Enabled” and ‘excel.exe’ is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE Criteria: If the value excel.exe is REG_DWORD = 1, this is not a finding.
Set the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Disable user name and password” to “Enabled” and select the "excel.exe" check box.
Validate the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Bind to Object” is set to “Enabled” and "excel.exe" check box is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT Criteria: If the value excel.exe is REG_DWORD = 1, this is not a finding.
Set the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Bind to Object” to “Enabled” and select the "excel.exe" check box.
Validate the policy value for Computer Configuration -> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Saved from URL” is set to “Enabled” and "excel.exe" check box is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK Criteria: If the value excel.exe is REG_DWORD = 1, this is not a finding.
Set the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Saved from URL” to “Enabled” and select the "excel.exe" check box.
Validate the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Navigate URL” is set to “Enabled” and "excel.exe" check box is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL Criteria: If the value excel.exe is REG_DWORD = 1, this is not a finding.
Set the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Navigate URL” to “Enabled” and select the "excel.exe" check box.
Validate the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Block popups” is set to “Enabled” and "excel.exe" check box is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT Criteria: If the value excel.exe is REG_DWORD = 1, this is not a finding.
Set the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Block popups” to “Enabled” and select the "excel.exe" check box.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center “Disable Trust Bar Notification for unsigned application add-ins” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security Criteria: If the value NoTBPromptUnsignedAddin is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center “Disable Trust Bar Notification for unsigned application add-ins” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2007 system -> Office 2007 Converters “Block opening of pre-release versions of file formats new to Excel 2007 through the Compatibility Pack for the 2007 Office system and Excel 2007 Converter” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security\FileOpenBlock Criteria: If the value Excel12BetaFilesFromConverters is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2007 system -> Office 2007 Converters “Block opening of pre-release versions of file formats new to Excel 2007 through the Compatibility Pack for the 2007 Office system and Excel 2007 Converter” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center -> Trusted Locations “Disable all trusted locations” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security\Trusted Locations Criteria: If the value AllLocationsDisabled is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center -> Trusted Locations “Disable all trusted locations” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security “Determine whether to force encrypted macros to be scanned in Microsoft Excel Open XML workbooks” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security Criteria: If the value ExcelBypassEncryptedMacroScan is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security “Determine whether to force encrypted macros to be scanned in Microsoft Excel Open XML workbooks” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Block file formats -> Save “Block saving of Open XML file types” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security\FileSaveBlock Criteria: If the value OpenXmlFiles is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Block file formats -> Save “Block saving of Open XML file types” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Block file formats -> Open “Block opening of files created by pre-release versions of Excel 2007” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security\FileOpenBlock Criteria: If the value Excel12BetaFiles is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Block file formats -> Open “Block opening of files created by pre-release versions of Excel 2007” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Block file formats -> Open “Block opening of Open XML file types” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security\FileOpenBlock Criteria: If the value OpenXmlFiles is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Block file formats -> Open “Block opening of Open XML file types” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center -> Trusted Locations “Allow Trusted Locations not on the computer” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security\Trusted Locations Criteria: If the value AllowNetworkLocations is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center -> Trusted Locations “Allow Trusted Locations not on the computer” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Save "save excel files as" will be set to "Enabled (Excel 97-2003 Workbook(*.xls)" or "Enabled (Excel Workbook *.xlsx"). Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Options Criteria: If the value DefaultFormat is REG_DWORD = 38 (hex) or 56 (Decimal) for Excel 97-2003 or If the value DefaultFormat is REG_DWORD = 33 (hex) or 51 (Decimal) for 2007 .xlsx , this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Save "save excel files as" will be set to "Enabled (Excel 97-2003 Workbook(*.xls)" or "Enabled (Excel Workbook *.xlsx").
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center “Trust access to Visual Basic Project” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security Criteria: If the value AccessVBOM is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center “Trust access to Visual Basic Project” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center “VBA macro warning settings” will be set to “Enabled (Trust Bar warning for all macros)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security Criteria: If the value VBAWarnings is REG_DWORD = 2, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center “VBA macro warning settings” will be set to “Enabled (Trust Bar warning for all macros)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security “Force file extension to match file type” will be set to “Enabled (Allow different, but warn)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security Criteria: If the value ExtensionHardening is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security “Force file extension to match file type” will be set to “Enabled (Allow different, but warn)”.
Validate the policy value for User Configuration >> Administrative Templates >> Microsoft Office Excel 2007 >> Excel Options >> Proofing >> Autocorrect Options “Internet and network paths as hyperlinks” is set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Options Criteria: If the value AutoHyperlink exists, this is a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Proofing -> Autocorrect Options “Internet and network paths as hyperlinks” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Save “Disable AutoRepublish” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Options Criteria: If the value DisableAutoRepublish is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Save “Disable AutoRepublish” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Advanced “Ask to update automatic links” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Options\BinaryOptions Criteria: If the value fUpdateExt_78_1 is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Advanced “Ask to update automatic links” will be set to “Enabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Save “AutoRepublish Warning Alert” will be set to “Enabled (Always show the alert before publishing)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Options Criteria: If the value DisableAutoRepublishWarning is REG_DWORD = 0, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Save “AutoRepublish Warning Alert” will be set to “Enabled (Always show the alert before publishing)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Advanced -> Web Options -> General “Load pictures from Web pages not created in Excel” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Internet Criteria: If the value DoNotLoadPictures is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Advanced -> Web Options -> General “Load pictures from Web pages not created in Excel” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Advanced -> Web Options -> General “Save any additional data necessary to maintain formulas” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Internet Criteria: If the value DoNotSaveHiddenData is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Advanced -> Web Options -> General “Save any additional data necessary to maintain formulas” will be set to “Disabled”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center “Store macro in Personal Macro Workbook by default” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Options\BinaryOptions Criteria: If the value fGlobalSheet_37_1 is REG_DWORD = 1, this is not a finding.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Excel Options -> Security -> Trust Center “Store macro in Personal Macro Workbook by default” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Options\BinaryOptions Criteria: If the value fGlobalSheet_37_1 is REG_DWORD = 1, this is not a finding.
To determine what service pack level is installed, start the Office application. Click on the Office Menu Button (upper left), click "Options" at the bottom of the menu, and select "Resources" from the left column. The version number will be displayed alongside the "About" button on the right-hand side display. If the "About" box information displays an Office 2007 version, this is a finding.
Upgrade to Office 2010, Office 2013, or Office 2016.