Microsoft Office System 2010 Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates +37 −38
Comparison against the immediately-prior release (V1R10). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Added rules 37
- V-241931 Medium Access to updates, add-ins, and patches on Office.com must be disabled.
- V-241932 Medium Upload of document templates to Office Online must be prevented.
- V-241933 Medium Documents must be configured to not open as Read Write when browsing.
- V-241934 Medium Vector markup Language (VML) for displaying graphics in browsers must be disallowed.
- V-241935 Medium The Help Improve Proofing Tools feature for Office must be configured.
- V-241936 Medium The Opt-In Wizard must be disabled.
- V-241937 Medium The Customer Experience Improvement Program for Office must be disabled.
- V-241938 Medium Automatic receiving of small updates to improve reliability must be disallowed.
- V-241939 Medium Trust Bar notifications for Security messages must be enforced.
- V-241940 Medium Rights managed Office Open XML files must be protected.
- V-241941 Medium Document metadata for password protected files must be protected.
- V-241942 Medium The encryption type for password protected Open XML files must be set.
- V-241943 Medium The encryption type for password protected Office 97 thru Office 2003 must be set.
- V-241944 Medium ActiveX control initialization must be disabled.
- V-241945 Medium Load controls in forms3 must be disabled from loading.
- V-241946 Medium Automation Security to enforce macro level security in Office documents must be configured.
- V-241947 Medium Hyperlink warnings for Office must be configured for use.
- V-241948 Medium Passwords for secured documents must be enforced.
- V-241949 Medium A mix of policy and user locations for Office Products must be disallowed.
- V-241950 Medium Smart Documents use of Manifests in Office must be disallowed.
- V-241951 Medium The Internet Fax Feature must be disabled.
- V-241952 Medium Changing permissions on rights managed content for users must be enforced.
- V-241953 Medium Office must be configured to not allow read with browsers.
- V-241954 Medium Connection verification of permissions must be enforced.
- V-241955 Medium Microsoft passport Service for content must be disallowed.
- V-241956 Medium Legacy format signatures must be enabled.
- V-241957 Medium External Signature Services Menu for Office must be suppressed.
- V-241958 Medium Inclusion of document properties for PDF and XPS output must be disallowed.
- V-241959 Medium Document Information panel Beaconing must show UI.
- V-241960 Medium Office client polling of Sharepoint servers published links must be disabled.
- V-241961 Medium Blogging entries created from inside Office products must be configured for Sharepoint only.
- V-241962 Medium Hyperlinks to web templates in File | New and task panes must be disabled.
- V-241963 Medium Office Live Workspace Integration must be off.
- V-241964 Medium Key Usage Filtering must be allowed.
- V-241965 Medium Customer-submitted templates downloads from Office.com must be disallowed.
- V-241966 Medium Encrypt document properties must be configured for OLE documents.
- V-241967 Medium Online content options must be configured for offline content availability.
Removed rules 38
- V-17547 Medium ActiveX control initialization must be disabled.
- V-17560 Medium A mix of policy and user locations for Office Products must be disallowed.
- V-17561 Low Choice of output to include PNG (Portable Network Graphics) must be disallowed.
- V-17581 Medium Blogging entries created from inside Office products must be configured for Sharepoint only.
- V-17583 Medium Office must be configured to not allow read with browsers.
- V-17588 Medium Access to updates, add-ins, and patches on Office.com must be disabled.
- V-17590 Medium Trust Bar notifications for Security messages must be enforced.
- V-17605 Medium Document Information panel Beaconing must show UI.
- V-17612 Medium The Customer Experience Improvement Program for Office must be disabled.
- V-17617 Medium The encryption type for password protected Office 97 thru Office 2003 must be set.
- V-17619 Medium The encryption type for password protected Open XML files must be set.
- V-17627 Medium The Help Improve Proofing Tools feature for Office must be configured.
- V-17659 Medium Hyperlink warnings for Office must be configured for use.
- V-17660 Medium Inclusion of document properties for PDF and XPS output must be disallowed.
- V-17661 Medium The Internet Fax Feature must be disabled.
- V-17662 Medium Microsoft passport Service for content must be disallowed.
- V-17664 Medium The Opt-In Wizard must be disabled.
- V-17665 Medium Passwords for secured documents must be enforced.
- V-17669 Medium Smart Documents use of Manifests in Office must be disallowed.
- V-17670 Medium Office client polling of Sharepoint servers published links must be disabled.
- V-17731 Medium Connection verification of permissions must be enforced.
- V-17740 Medium Automatic receiving of small updates to improve reliability must be disallowed.
- V-17741 Medium Automation Security to enforce macro level security in Office documents must be configured.
- V-17749 Medium Legacy format signatures must be enabled.
- V-17750 Medium Load controls in forms3 must be disabled from loading.
- V-17759 Medium Documents must be configured to not open as Read Write when browsing.
- V-17765 Medium Changing permissions on rights managed content for users must be enforced.
- V-17767 Medium Upload of document templates to Office Online must be prevented.
- V-17768 Medium Document metadata for password protected files must be protected.
- V-17769 Medium Rights managed Office Open XML files must be protected.
- V-17773 Medium Vector markup Language (VML) for displaying graphics in browsers must be disallowed.
- V-17805 Medium External Signature Services Menu for Office must be suppressed.
- V-26626 Medium Hyperlinks to web templates in File | New and task panes must be disabled.
- V-26627 Medium Office Live Workspace Integration must be off.
- V-26629 Medium Key Usage Filtering must be allowed.
- V-26630 Medium Online content options must be configured for offline content availability.
- V-26631 Medium Customer-submitted templates downloads from Office.com must be disallowed.
- V-26704 Medium Encrypt document properties must be configured for OLE documents.
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001749
- Version
- DTOO177 - Office System
- Vuln IDs
-
- V-241931
- Rule IDs
-
- SV-241931r960954_rule
Checks: C-45206r849842_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... "Disable access to updates, add-ins, and patches on Office.com" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value DisableDownloadCenterAccess is REG_DWORD = 1, this is not a finding.
Fix: F-45165r698030_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... "Disable access to updates, add-ins, and patches on Office.com" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DTOO178 - Office System
- Vuln IDs
-
- V-241932
- Rule IDs
-
- SV-241932r961863_rule
Checks: C-45207r698095_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... "Prevent users from uploading document templates to the Office.com Community" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value DisableCustomerSubmittedUpload is REG_DWORD = 1, this is not a finding.
Fix: F-45166r698096_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... "Prevent users from uploading document templates to the Office.com Community" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO179 - Office System
- Vuln IDs
-
- V-241933
- Rule IDs
-
- SV-241933r961092_rule
Checks: C-45208r698089_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... -> Files "Open Office documents as read/write while browsing" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value OpenDocumentsReadWriteWhileBrowsing is REG_DWORD = 0, this is not a finding.
Fix: F-45167r698090_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... -> Files "Open Office documents as read/write while browsing" to "Disabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO180 - Office System
- Vuln IDs
-
- V-241934
- Rule IDs
-
- SV-241934r961092_rule
Checks: C-45209r698104_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options -> Browsers "Rely on VML for displaying graphics in browsers" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value RelyOnVML is REG_DWORD = 0, this is not a finding.
Fix: F-45168r698105_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options -> Browsers "Rely on VML for displaying graphics in browsers" to "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DTOO182 - Office System
- Vuln IDs
-
- V-241935
- Rule IDs
-
- SV-241935r961863_rule
Checks: C-45210r698047_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ Spelling -> Proofing Data Collection "Improve Proofing Tools" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\ptwatson Criteria: If the value PTWOptIn is REG_DWORD = 0, this is not a finding.
Fix: F-45169r698048_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ Spelling -> Proofing Data Collection "Improve Proofing Tools" to "Disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTOO183 - Office System
- Vuln IDs
-
- V-241936
- Rule IDs
-
- SV-241936r960963_rule
Checks: C-45211r698062_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Privacy -> Trust Center "Disable Opt-in Wizard on first run" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\general Criteria: If the value ShownFirstRunOptin is REG_DWORD = 1, this is not a finding.
Fix: F-45170r698063_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Privacy -> Trust Center "Disable Opt-in Wizard on first run" to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTOO184 - Office System
- Vuln IDs
-
- V-241937
- Rule IDs
-
- SV-241937r960963_rule
Checks: C-45212r698038_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Privacy -> Trust Center "Enable Customer Experience Improvement Program" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common Criteria: If the value QMEnable is REG_DWORD =0, this is not a finding.
Fix: F-45171r698039_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Privacy -> Trust Center "Enable Customer Experience Improvement Program" to "Disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTOO185 - Office System
- Vuln IDs
-
- V-241938
- Rule IDs
-
- SV-241938r960963_rule
Checks: C-45213r698077_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Privacy -> Trust Center "Automatically receive small updates to improve reliability" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common Criteria: If the value UpdateReliabilityData is REG_DWORD = 0, this is not a finding.
Fix: F-45172r698078_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Privacy -> Trust Center "Automatically receive small updates to improve reliability" to :Disabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001662
- Version
- DTOO186 - Office System
- Vuln IDs
-
- V-241939
- Rule IDs
-
- SV-241939r961086_rule
Checks: C-45214r698032_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Disable all Trust Bar notifications for security issues" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\trustcenter Criteria: If the value TrustBar is REG_DWORD = 0, this is not a finding.
Fix: F-45173r698137_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Disable all Trust Bar notifications for security issues" to "Disabled".
- RMF Control
- SC-28
- Severity
- M
- CCI
- CCI-002476
- Version
- DTOO187 - Office System
- Vuln IDs
-
- V-241940
- Rule IDs
-
- SV-241940r961602_rule
Checks: C-45215r849844_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Protect document metadata for rights managed Office Open XML Files" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value DRMEncryptProperty is REG_DWORD = 1, this is not a finding.
Fix: F-45174r698102_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Protect document metadata for rights managed Office Open XML Files" to "Enabled".
- RMF Control
- SC-28
- Severity
- M
- CCI
- CCI-001199
- Version
- DTOO188 - Office System
- Vuln IDs
-
- V-241941
- Rule IDs
-
- SV-241941r961128_rule
Checks: C-45216r698098_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Protect document metadata for password protected files" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value OpenXMLEncryptProperty is REG_DWORD = 1, this is not a finding.
Fix: F-45175r698099_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Protect document metadata for password protected files" to "Enabled".
- RMF Control
- SC-28
- Severity
- M
- CCI
- CCI-001199
- Version
- DTOO189 - Office System
- Vuln IDs
-
- V-241942
- Rule IDs
-
- SV-241942r961128_rule
Checks: C-45217r698044_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Encryption type for password protected Office Open XML files" must be set to "Enabled (Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value OpenXMLEncryption is REG_SZ = "Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256", this is not a finding.
Fix: F-45176r698045_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Encryption type for password protected Office Open XML files" to "Enabled (Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256)".
- RMF Control
- SC-28
- Severity
- M
- CCI
- CCI-001199
- Version
- DTOO190 - Office System
- Vuln IDs
-
- V-241943
- Rule IDs
-
- SV-241943r961128_rule
Checks: C-45218r698139_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Encryption type for password protected Office 97-2003 files" must be set to "Enabled (Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value DefaultEncryption12 is REG_SZ = "Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256", this is not a finding.
Fix: F-45177r698042_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Encryption type for password protected Office 97-2003 files" to "Enabled (Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256)".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-002460
- Version
- DTOO191 - Office System
- Vuln IDs
-
- V-241944
- Rule IDs
-
- SV-241944r961779_rule
Checks: C-45219r849846_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "ActiveX Control Initialization" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\Common\Security Criteria: If the value UFIControls exists, this is a finding.
Fix: F-45178r698018_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "ActiveX Control Initialization" to "Disabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001662
- Version
- DTOO192 - Office System
- Vuln IDs
-
- V-241945
- Rule IDs
-
- SV-241945r961086_rule
Checks: C-45220r698086_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Security Settings "Load Controls in Forms" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\VBA\Security Criteria: If the value LoadControlsInForms exists, this is a finding.
Fix: F-45179r698087_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Security Settings "Load Controls in Forms" to "Disabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO193 - Office System
- Vuln IDs
-
- V-241946
- Rule IDs
-
- SV-241946r961092_rule
Checks: C-45221r698080_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Security Settings "Automation Security" must be "Enabled (Use application macro security level)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\Common\Security Criteria: If the value AutomationSecurity is REG_DWORD = 2, this is not a finding.
Fix: F-45180r698081_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Security Settings "Automation Security" to "Enabled (Use application macro security level)".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-002460
- Version
- DTOO194 - Office System
- Vuln IDs
-
- V-241947
- Rule IDs
-
- SV-241947r961779_rule
Checks: C-45222r849848_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Suppress hyperlink warnings" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value DisableHyperLinkWarning is REG_DWORD = 0, this is not a finding.
Fix: F-45181r698051_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Suppress hyperlink warnings" to "Disabled".
- RMF Control
- SC-28
- Severity
- M
- CCI
- CCI-001199
- Version
- DTOO195 - Office System
- Vuln IDs
-
- V-241948
- Rule IDs
-
- SV-241948r961128_rule
Checks: C-45223r698065_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Security Settings "Disable password to open UI" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value DisablePasswordUI is REG_DWORD = 0, this is not a finding.
Fix: F-45182r698066_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Security Settings "Disable password to open UI" to "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DTOO196 - Office System
- Vuln IDs
-
- V-241949
- Rule IDs
-
- SV-241949r961863_rule
Checks: C-45224r698020_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings -> Trust Center "Allow mix of policy and user locations" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security\trusted locations Criteria: If the value Allow User Locations is REG_DWORD = 0, this is not a finding.
Fix: F-45183r698021_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings -> Trust Center "Allow mix of policy and user locations" to "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DTOO197 - Office System
- Vuln IDs
-
- V-241950
- Rule IDs
-
- SV-241950r961863_rule
Checks: C-45225r698068_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Smart Documents (Word, Excel) "Disable Smart Document's use of manifests" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\Common\Smart Tag Criteria: If the value NeverLoadManifests is REG_DWORD = 1, this is not a finding.
Fix: F-45184r698069_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Smart Documents (Word, Excel) "Disable Smart Document's use of manifests" to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTOO198 - Office System
- Vuln IDs
-
- V-241951
- Rule IDs
-
- SV-241951r960963_rule
Checks: C-45226r698056_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Services -> Fax "Disable Internet Fax feature" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\services\fax Criteria: If the value NoFax is REG_DWORD = 1, this is not a finding.
Fix: F-45185r698057_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Services -> Fax "Disable Internet Fax feature" to "Enabled".
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-002165
- Version
- DTOO199 - Office System
- Vuln IDs
-
- V-241952
- Rule IDs
-
- SV-241952r961317_rule
Checks: C-45227r849850_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions "Prevent users from changing permissions on rights managed content" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\drm Criteria: If the value DisableCreation is REG_DWORD = 0, this is not a finding.
Fix: F-45186r698093_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions "Prevent users from changing permissions on rights managed content" to "Disabled".
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-002165
- Version
- DTOO200 - Office System
- Vuln IDs
-
- V-241953
- Rule IDs
-
- SV-241953r961317_rule
Checks: C-45228r849852_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions "Allow users with earlier versions of Office to read with browsers" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\drm Criteria: If the value IncludeHTML is REG_DWORD = 0, this is not a finding.
Fix: F-45187r849853_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions "Allow users with earlier versions of Office to read with browsers" to "Disabled".
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- DTOO201 - Office System
- Vuln IDs
-
- V-241954
- Rule IDs
-
- SV-241954r961353_rule
Checks: C-45229r849855_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions "Always require users to connect to verify permission" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\drm Criteria: If the value RequireConnection is REG_DWORD = 1, this is not a finding.
Fix: F-45188r698075_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions "Always require users to connect to verify permission" to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTOO202 - Office System
- Vuln IDs
-
- V-241955
- Rule IDs
-
- SV-241955r960963_rule
Checks: C-45230r698059_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions "Disable Microsoft Passport service for content with restricted permission" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\drm Criteria: If the value DisablePassportCertification is REG_DWORD = 1, this is not a finding.
Fix: F-45189r698060_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions "Disable Microsoft Passport service for content with restricted permission" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DTOO203 - Office System
- Vuln IDs
-
- V-241956
- Rule IDs
-
- SV-241956r961863_rule
Checks: C-45231r698083_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing "Legacy format signatures" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\signatures Criteria: If the value XPCompatibleSignatureFormat is REG_DWORD = 1, this is not a finding.
Fix: F-45190r698084_fix
Set he policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing "Legacy format signatures" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DTOO204 - Office System
- Vuln IDs
-
- V-241957
- Rule IDs
-
- SV-241957r961863_rule
Checks: C-45232r698108_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing "Suppress external signature services menu item" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\signatures Criteria: If the value SuppressExtSigningSvcs is REG_DWORD = 1, this is not a finding.
Fix: F-45191r698109_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing "Suppress external signature services menu item" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DTOO206 - Office System
- Vuln IDs
-
- V-241958
- Rule IDs
-
- SV-241958r961863_rule
Checks: C-45233r698053_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Microsoft Save As PDF and XPS add-ins "Disable inclusion of document properties in PDF and XPS output" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\fixedformat Criteria: If the value DisableFixedFormatDocProperties is REG_DWORD = 1, this is not a finding.
Fix: F-45192r698054_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Microsoft Save As PDF and XPS add-ins "Disable inclusion of document properties in PDF and XPS output" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-002460
- Version
- DTOO207 - Office System
- Vuln IDs
-
- V-241959
- Rule IDs
-
- SV-241959r961779_rule
Checks: C-45234r849857_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Document Information Panel "Document Information Panel Beaconing UI" must be set to "Enabled (Always show UI)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\documentinformationpanel Criteria: If the value Beaconing is REG_DWORD = 1, this is not a finding.
Fix: F-45193r698036_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Document Information Panel "Document Information Panel Beaconing UI" to "Enabled (Always show UI)".
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- DTOO208 - Office System
- Vuln IDs
-
- V-241960
- Rule IDs
-
- SV-241960r960792_rule
Checks: C-45235r698071_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Server Settings "Disable the Office client from polling the SharePoint Server for published links" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\portal Criteria: If the value LinkPublishingDisabled is REG_DWORD = 1, this is not a finding.
Fix: F-45194r698072_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Server Settings "Disable the Office client from polling the SharePoint Server for published links" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DTOO212 - Office System
- Vuln IDs
-
- V-241961
- Rule IDs
-
- SV-241961r961863_rule
Checks: C-45236r698023_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Miscellaneous "Control Blogging" must be "Enabled (Only SharePoint blogs allowed)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\Common\Blog Criteria: If the value DisableBlog is REG_DWORD = 1, this is not a finding.
Fix: F-45195r698024_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Miscellaneous "Control Blogging" to "Enabled (Only SharePoint blogs allowed)".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTOO306 - Office System
- Vuln IDs
-
- V-241962
- Rule IDs
-
- SV-241962r960963_rule
Checks: C-45237r698111_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Miscellaneous "Disable hyperlinks to web templates in File | New and task panes" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value DisableTemplatesOnTheWeb is REG_DWORD = 1, this is not a finding.
Fix: F-45196r698112_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Miscellaneous "Disable hyperlinks to web templates in File | New and task panes" to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTOO307 - Office System
- Vuln IDs
-
- V-241963
- Rule IDs
-
- SV-241963r960963_rule
Checks: C-45238r698114_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Office Live Workspace "Turn Off Office Live Workspace Integration" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\officeliveworkspace Criteria: If the value TurnOffOfficeLiveWorkspaceIntegration is REG_DWORD = 1, this is not a finding.
Fix: F-45197r698115_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Office Live Workspace "Turn Off Office Live Workspace Integration" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DTOO311 - Office System
- Vuln IDs
-
- V-241964
- Rule IDs
-
- SV-241964r961863_rule
Checks: C-45239r698117_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing "Key Usage Filtering" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\general Criteria: If the value FilterDigitalSignatureCert is REG_DWORD = 1, this is not a finding.
Fix: F-45198r698118_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing "Key Usage Filtering" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO312 - Office System
- Vuln IDs
-
- V-241965
- Rule IDs
-
- SV-241965r961092_rule
Checks: C-45240r698123_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools | Options | General | Web Options... "Disable customer-submitted templates downloads from Office.com" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value DisableCustomerSubmittedDownload is REG_DWORD = 1, this is not a finding.
Fix: F-45199r698124_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools | Options | General | Web Options... "Disable customer-submitted templates downloads from Office.com" to "Enabled".
- RMF Control
- SC-28
- Severity
- M
- CCI
- CCI-002476
- Version
- DTOO321 - Office System
- Vuln IDs
-
- V-241966
- Rule IDs
-
- SV-241966r961602_rule
Checks: C-45241r849859_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Encrypt document properties" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value EncryptDocProps is REG_DWORD = 1, this is not a finding.
Fix: F-45200r698127_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings "Encrypt document properties" to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTOO345 - Office System
- Vuln IDs
-
- V-241967
- Rule IDs
-
- SV-241967r960963_rule
Checks: C-45242r698120_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools | Options | General | Service Options... -> Online Content "Online content options" must be set to "Enabled: Search only offline content whenever available". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value UseOnlineContent is REG_DWORD = 1, this is not a finding.
Fix: F-45201r698121_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools | Options | General | Service Options... -> Online Content "Online content options" to "Enabled: Search only offline content whenever available".