Select any two versions of this STIG to compare the individual requirements
Select any old version/release of this STIG to view the previous requirements
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... "Disable access to updates, add-ins, and patches on Office.com" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value DisableDownloadCenterAccess is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... "Disable access to updates, add-ins, and patches on Office.com" to "Enabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... "Prevent users from uploading document templates to the Office.com Community" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value DisableCustomerSubmittedUpload is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... "Prevent users from uploading document templates to the Office.com Community" to "Enabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... -> Files "Open Office documents as read/write while browsing" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value OpenDocumentsReadWriteWhileBrowsing is REG_DWORD = 0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... -> Files "Open Office documents as read/write while browsing" to "Disabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options -> Browsers "Rely on VML for displaying graphics in browsers" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value RelyOnVML is REG_DWORD = 0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options -> Browsers "Rely on VML for displaying graphics in browsers" to "Disabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ Spelling -> Proofing Data Collection "Improve Proofing Tools" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\ptwatson Criteria: If the value PTWOptIn is REG_DWORD = 0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ Spelling -> Proofing Data Collection "Improve Proofing Tools" to "Disabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Privacy -> Trust Center "Disable Opt-in Wizard on first run" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\general Criteria: If the value ShownFirstRunOptin is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Privacy -> Trust Center "Disable Opt-in Wizard on first run" to "Enabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Privacy -> Trust Center "Enable Customer Experience Improvement Program" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common Criteria: If the value QMEnable is REG_DWORD =0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Privacy -> Trust Center "Enable Customer Experience Improvement Program" to "Disabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Privacy -> Trust Center "Automatically receive small updates to improve reliability" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common Criteria: If the value UpdateReliabilityData is REG_DWORD = 0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Privacy -> Trust Center "Automatically receive small updates to improve reliability" to :Disabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Disable all Trust Bar notifications for security issues" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\trustcenter Criteria: If the value TrustBar is REG_DWORD = 0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Disable all Trust Bar notifications for security issues" to "Disabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Protect document metadata for rights managed Office Open XML Files" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value DRMEncryptProperty is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Protect document metadata for rights managed Office Open XML Files" to "Enabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Protect document metadata for password protected files" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value OpenXMLEncryptProperty is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Protect document metadata for password protected files" to "Enabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Encryption type for password protected Office Open XML files" must be set to "Enabled (Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value OpenXMLEncryption is REG_SZ = "Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256", this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Encryption type for password protected Office Open XML files" to "Enabled (Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256)".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Encryption type for password protected Office 97-2003 files" must be set to "Enabled (Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value DefaultEncryption12 is REG_SZ = "Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256", this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Encryption type for password protected Office 97-2003 files" to "Enabled (Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256)".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "ActiveX Control Initialization" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\Common\Security Criteria: If the value UFIControls exists, this is a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "ActiveX Control Initialization" to "Disabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Security Settings "Load Controls in Forms" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\VBA\Security Criteria: If the value LoadControlsInForms exists, this is a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Security Settings "Load Controls in Forms" to "Disabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Security Settings "Automation Security" must be "Enabled (Use application macro security level)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\Common\Security Criteria: If the value AutomationSecurity is REG_DWORD = 2, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Security Settings "Automation Security" to "Enabled (Use application macro security level)".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Suppress hyperlink warnings" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value DisableHyperLinkWarning is REG_DWORD = 0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Suppress hyperlink warnings" to "Disabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Security Settings "Disable password to open UI" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value DisablePasswordUI is REG_DWORD = 0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Security Settings "Disable password to open UI" to "Disabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings -> Trust Center "Allow mix of policy and user locations" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security\trusted locations Criteria: If the value Allow User Locations is REG_DWORD = 0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings -> Trust Center "Allow mix of policy and user locations" to "Disabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Smart Documents (Word, Excel) "Disable Smart Document's use of manifests" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\Common\Smart Tag Criteria: If the value NeverLoadManifests is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Smart Documents (Word, Excel) "Disable Smart Document's use of manifests" to "Enabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Services -> Fax "Disable Internet Fax feature" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\services\fax Criteria: If the value NoFax is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Services -> Fax "Disable Internet Fax feature" to "Enabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions "Prevent users from changing permissions on rights managed content" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\drm Criteria: If the value DisableCreation is REG_DWORD = 0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions "Prevent users from changing permissions on rights managed content" to "Disabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions "Allow users with earlier versions of Office to read with browsers" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\drm Criteria: If the value IncludeHTML is REG_DWORD = 0, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions "Allow users with earlier versions of Office to read with browsers" to "Disabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions "Always require users to connect to verify permission" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\drm Criteria: If the value RequireConnection is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions "Always require users to connect to verify permission" to "Enabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions "Disable Microsoft Passport service for content with restricted permission" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\drm Criteria: If the value DisablePassportCertification is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions "Disable Microsoft Passport service for content with restricted permission" to "Enabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing "Legacy format signatures" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\signatures Criteria: If the value XPCompatibleSignatureFormat is REG_DWORD = 1, this is not a finding.
Set he policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing "Legacy format signatures" to "Enabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing "Suppress external signature services menu item" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\signatures Criteria: If the value SuppressExtSigningSvcs is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing "Suppress external signature services menu item" to "Enabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Microsoft Save As PDF and XPS add-ins "Disable inclusion of document properties in PDF and XPS output" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\fixedformat Criteria: If the value DisableFixedFormatDocProperties is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Microsoft Save As PDF and XPS add-ins "Disable inclusion of document properties in PDF and XPS output" to "Enabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Document Information Panel "Document Information Panel Beaconing UI" must be set to "Enabled (Always show UI)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\documentinformationpanel Criteria: If the value Beaconing is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Document Information Panel "Document Information Panel Beaconing UI" to "Enabled (Always show UI)".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Server Settings "Disable the Office client from polling the SharePoint Server for published links" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\portal Criteria: If the value LinkPublishingDisabled is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Server Settings "Disable the Office client from polling the SharePoint Server for published links" to "Enabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Miscellaneous "Control Blogging" must be "Enabled (Only SharePoint blogs allowed)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\Common\Blog Criteria: If the value DisableBlog is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Miscellaneous "Control Blogging" to "Enabled (Only SharePoint blogs allowed)".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Miscellaneous "Disable hyperlinks to web templates in File | New and task panes" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value DisableTemplatesOnTheWeb is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Miscellaneous "Disable hyperlinks to web templates in File | New and task panes" to "Enabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Office Live Workspace "Turn Off Office Live Workspace Integration" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\officeliveworkspace Criteria: If the value TurnOffOfficeLiveWorkspaceIntegration is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Office Live Workspace "Turn Off Office Live Workspace Integration" to "Enabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing "Key Usage Filtering" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\general Criteria: If the value FilterDigitalSignatureCert is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing "Key Usage Filtering" to "Enabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools | Options | General | Web Options... "Disable customer-submitted templates downloads from Office.com" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value DisableCustomerSubmittedDownload is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools | Options | General | Web Options... "Disable customer-submitted templates downloads from Office.com" to "Enabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Encrypt document properties" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value EncryptDocProps is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Encrypt document properties" to "Enabled".
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools | Options | General | Service Options... -> Online Content "Online content options" must be set to "Enabled: Search only offline content whenever available". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value UseOnlineContent is REG_DWORD = 1, this is not a finding.
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools | Options | General | Service Options... -> Online Content "Online content options" to "Enabled: Search only offline content whenever available".