Microsoft Office System 2010
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates No substantive changes
Comparison against the immediately-prior release (V1R8). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
No substantive changes detected against the previous release. 38 rules matched cleanly.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO191 - Office System
- Vuln IDs
-
- V-17547
- Rule IDs
-
- SV-33453r1_rule
Checks: C-33936r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “ActiveX Control Initialization” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\Common\Security Criteria: If the value UFIControls exists, this is a finding.
Fix: F-29625r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “ActiveX Control Initialization” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO196 - Office System
- Vuln IDs
-
- V-17560
- Rule IDs
-
- SV-33470r1_rule
Checks: C-33953r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings -> Trust Center “Allow mix of policy and user locations” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security\trusted locations Criteria: If the value Allow User Locations is REG_DWORD = 0, this is not a finding.
Fix: F-29642r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings -> Trust Center “Allow mix of policy and user locations” to “Disabled”.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- DTOO181 - Office System
- Vuln IDs
-
- V-17561
- Rule IDs
-
- SV-33478r1_rule
Checks: C-33961r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options -> Browsers “Allow PNG as an output format” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value AllowPNG is REG_DWORD = 0, this is not a finding.
Fix: F-29650r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options -> Browsers “Allow PNG as an output format” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO212 - Office System
- Vuln IDs
-
- V-17581
- Rule IDs
-
- SV-33464r1_rule
Checks: C-33947r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Miscellaneous “Control Blogging” must be “Enabled (Only SharePoint blogs allowed)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\Common\Blog Criteria: If the value DisableBlog is REG_DWORD = 1, this is not a finding.
Fix: F-29636r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Miscellaneous “Control Blogging” to “Enabled (Only SharePoint blogs allowed)”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO200 - Office System
- Vuln IDs
-
- V-17583
- Rule IDs
-
- SV-33459r1_rule
Checks: C-33942r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions “Allow users with earlier versions of Office to read with browsers” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\drm Criteria: If the value IncludeHTML is REG_DWORD = 0, this is not a finding.
Fix: F-29631r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions “Allow users with earlier versions of Office to read with browsers” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO177 - Office System
- Vuln IDs
-
- V-17588
- Rule IDs
-
- SV-33476r1_rule
Checks: C-33959r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... “Disable access to updates, add-ins, and patches on Office.com” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value DisableDownloadCenterAccess is REG_DWORD = 1, this is not a finding.
Fix: F-29648r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... “Disable access to updates, add-ins, and patches on Office.com” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO186 - Office System
- Vuln IDs
-
- V-17590
- Rule IDs
-
- SV-33455r1_rule
Checks: C-33938r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Disable all Trust Bar notifications for security issues” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\trustcenter Criteria: If the value TrustBar is REG_DWORD = 0, this is not a finding.
Fix: F-29627r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Disable all Trust Bar notifications for security issues” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO207 - Office System
- Vuln IDs
-
- V-17605
- Rule IDs
-
- SV-33458r1_rule
Checks: C-33941r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Document Information Panel “Document Information Panel Beaconing UI” must be set to “Enabled (Always show UI)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\documentinformationpanel Criteria: If the value Beaconing is REG_DWORD = 1, this is not a finding.
Fix: F-29630r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Document Information Panel “Document Information Panel Beaconing UI” to “Enabled (Always show UI)”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO184 - Office System
- Vuln IDs
-
- V-17612
- Rule IDs
-
- SV-33452r1_rule
Checks: C-33935r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Privacy -> Trust Center “Enable Customer Experience Improvement Program” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common Criteria: If the value QMEnable is REG_DWORD =0, this is not a finding.
Fix: F-29624r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Privacy -> Trust Center “Enable Customer Experience Improvement Program” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO190 - Office System
- Vuln IDs
-
- V-17617
- Rule IDs
-
- SV-33457r1_rule
Checks: C-33940r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Encryption type for password protected Office 97-2003 files” must be set to “Enabled (Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value DefaultEncryption12 is REG_SZ = “Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256", this is not a finding.
Fix: F-29629r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Encryption type for password protected Office 97-2003 files” to “Enabled (Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256)”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO189 - Office System
- Vuln IDs
-
- V-17619
- Rule IDs
-
- SV-33465r2_rule
Checks: C-33948r3_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Encryption type for password protected Office Open XML files” must be set to “Enabled (Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value OpenXMLEncryption is REG_SZ = “Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256”, this is not a finding.
Fix: F-29637r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Encryption type for password protected Office Open XML files” to “Enabled (Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256)”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO182 - Office System
- Vuln IDs
-
- V-17627
- Rule IDs
-
- SV-33481r1_rule
Checks: C-33964r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ Spelling -> Proofing Data Collection “Improve Proofing Tools” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\ptwatson Criteria: If the value PTWOptIn is REG_DWORD = 0, this is not a finding.
Fix: F-29653r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ Spelling -> Proofing Data Collection “Improve Proofing Tools” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO194 - Office System
- Vuln IDs
-
- V-17659
- Rule IDs
-
- SV-33469r1_rule
Checks: C-33952r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Suppress hyperlink warnings” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value DisableHyperLinkWarning is REG_DWORD = 0, this is not a finding.
Fix: F-29641r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Suppress hyperlink warnings” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO206 - Office System
- Vuln IDs
-
- V-17660
- Rule IDs
-
- SV-33463r1_rule
Checks: C-33946r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Microsoft Save As PDF and XPS add-ins “Disable inclusion of document properties in PDF and XPS output” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\fixedformat Criteria: If the value DisableFixedFormatDocProperties is REG_DWORD = 1, this is not a finding.
Fix: F-29635r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Microsoft Save As PDF and XPS add-ins “Disable inclusion of document properties in PDF and XPS output” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO198 - Office System
- Vuln IDs
-
- V-17661
- Rule IDs
-
- SV-33472r1_rule
Checks: C-33955r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Services -> Fax “Disable Internet Fax feature” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\services\fax Criteria: If the value NoFax is REG_DWORD = 1, this is not a finding.
Fix: F-29644r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Services -> Fax “Disable Internet Fax feature” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO202 - Office System
- Vuln IDs
-
- V-17662
- Rule IDs
-
- SV-33461r1_rule
Checks: C-33944r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions “Disable Microsoft Passport service for content with restricted permission” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\drm Criteria: If the value DisablePassportCertification is REG_DWORD = 1, this is not a finding.
Fix: F-29633r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions “Disable Microsoft Passport service for content with restricted permission” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO183 - Office System
- Vuln IDs
-
- V-17664
- Rule IDs
-
- SV-33931r1_rule
Checks: C-34373r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Privacy -> Trust Center “Disable Opt-in Wizard on first run” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\general Criteria: If the value ShownFirstRunOptin is REG_DWORD = 1, this is not a finding.
Fix: F-30009r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Privacy -> Trust Center “Disable Opt-in Wizard on first run” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO195 - Office System
- Vuln IDs
-
- V-17665
- Rule IDs
-
- SV-33456r1_rule
Checks: C-33939r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Security Settings “Disable password to open UI” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value DisablePasswordUI is REG_DWORD = 0, this is not a finding.
Fix: F-29628r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Security Settings “Disable password to open UI” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO197 - Office System
- Vuln IDs
-
- V-17669
- Rule IDs
-
- SV-33475r1_rule
Checks: C-33958r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Smart Documents (Word, Excel) “Disable Smart Document's use of manifests” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\Common\Smart Tag Criteria: If the value NeverLoadManifests is REG_DWORD = 1, this is not a finding.
Fix: F-29647r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Smart Documents (Word, Excel) “Disable Smart Document's use of manifests” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO208 - Office System
- Vuln IDs
-
- V-17670
- Rule IDs
-
- SV-33471r1_rule
Checks: C-33954r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Server Settings “Disable the Office client from polling the SharePoint Server for published links” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\portal Criteria: If the value LinkPublishingDisabled is REG_DWORD = 1, this is not a finding.
Fix: F-29643r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Server Settings “Disable the Office client from polling the SharePoint Server for published links" to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO201 - Office System
- Vuln IDs
-
- V-17731
- Rule IDs
-
- SV-33460r1_rule
Checks: C-33943r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions “Always require users to connect to verify permission” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\drm Criteria: If the value RequireConnection is REG_DWORD = 1, this is not a finding.
Fix: F-29632r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions “Always require users to connect to verify permission” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO185 - Office System
- Vuln IDs
-
- V-17740
- Rule IDs
-
- SV-33451r1_rule
Checks: C-33934r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Privacy -> Trust Center “Automatically receive small updates to improve reliability” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common Criteria: If the value UpdateReliabilityData is REG_DWORD = 0, this is not a finding.
Fix: F-29623r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Privacy -> Trust Center “Automatically receive small updates to improve reliability” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO193 - Office System
- Vuln IDs
-
- V-17741
- Rule IDs
-
- SV-33454r1_rule
Checks: C-33937r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Security Settings “Automation Security” must be "Enabled (Use application macro security level)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\Common\Security Criteria: If the value AutomationSecurity is REG_DWORD = 2, this is not a finding.
Fix: F-29626r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Security Settings “Automation Security” to “Enabled (Use application macro security level)”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO203 - Office System
- Vuln IDs
-
- V-17749
- Rule IDs
-
- SV-33473r1_rule
Checks: C-33956r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing “Legacy format signatures” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\signatures Criteria: If the value XPCompatibleSignatureFormat is REG_DWORD = 1, this is not a finding.
Fix: F-29645r1_fix
Set he policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing “Legacy format signatures” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO192 - Office System
- Vuln IDs
-
- V-17750
- Rule IDs
-
- SV-33466r1_rule
Checks: C-33949r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Security Settings “Load Controls in Forms3” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\VBA\Security Criteria: If the value LoadControlsInForms exists, this is a finding.
Fix: F-29638r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010-> Security Settings “Load Controls in Forms3” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO179 - Office System
- Vuln IDs
-
- V-17759
- Rule IDs
-
- SV-33480r1_rule
Checks: C-33963r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... -> Files “Open Office documents as read/write while browsing” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value OpenDocumentsReadWriteWhileBrowsing is REG_DWORD = 0, this is not a finding.
Fix: F-29652r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... -> Files “Open Office documents as read/write while browsing” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO199 - Office System
- Vuln IDs
-
- V-17765
- Rule IDs
-
- SV-33462r1_rule
Checks: C-33945r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions “Prevent users from changing permissions on rights managed content” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\drm Criteria: If the value DisableCreation is REG_DWORD = 0, this is not a finding.
Fix: F-29634r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions “Prevent users from changing permissions on rights managed content” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO178 - Office System
- Vuln IDs
-
- V-17767
- Rule IDs
-
- SV-33477r1_rule
Checks: C-33960r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... “Prevent users from uploading document templates to the Office.com Community” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value DisableCustomerSubmittedUpload is REG_DWORD = 1, this is not a finding.
Fix: F-29649r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... “Prevent users from uploading document templates to the Office.com Community” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO188 - Office System
- Vuln IDs
-
- V-17768
- Rule IDs
-
- SV-33467r1_rule
Checks: C-33950r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Protect document metadata for password protected files” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value OpenXMLEncryptProperty is REG_DWORD = 1, this is not a finding.
Fix: F-29639r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Protect document metadata for password protected files” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO187 - Office System
- Vuln IDs
-
- V-17769
- Rule IDs
-
- SV-33468r1_rule
Checks: C-33951r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Protect document metadata for rights managed Office Open XML Files” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value DRMEncryptProperty is REG_DWORD = 1, this is not a finding.
Fix: F-29640r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Protect document metadata for rights managed Office Open XML Files” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO180 - Office System
- Vuln IDs
-
- V-17773
- Rule IDs
-
- SV-33479r1_rule
Checks: C-33962r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options -> Browsers “Rely on VML for displaying graphics in browsers” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value RelyOnVML is REG_DWORD = 0, this is not a finding.
Fix: F-29651r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options -> Browsers “Rely on VML for displaying graphics in browsers” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO204 - Office System
- Vuln IDs
-
- V-17805
- Rule IDs
-
- SV-33474r1_rule
Checks: C-33957r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing “Suppress external signature services menu item” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\signatures Criteria: If the value SuppressExtSigningSvcs is REG_DWORD = 1, this is not a finding.
Fix: F-29646r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing “Suppress external signature services menu item” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO306 - Office System
- Vuln IDs
-
- V-26626
- Rule IDs
-
- SV-34082r1_rule
Checks: C-34221r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Miscellaneous “Disable hyperlinks to web templates in File | New and task panes” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value DisableTemplatesOnTheWeb is REG_DWORD = 1, this is not a finding.
Fix: F-29912r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Miscellaneous “Disable hyperlinks to web templates in File | New and task panes” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO307 - Office System
- Vuln IDs
-
- V-26627
- Rule IDs
-
- SV-34083r1_rule
Checks: C-34222r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Office Live Workspace “Turn Off Office Live Workspace Integration” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\officeliveworkspace Criteria: If the value TurnOffOfficeLiveWorkspaceIntegration is REG_DWORD = 1, this is not a finding.
Fix: F-29913r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Office Live Workspace “Turn Off Office Live Workspace Integration” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO311 - Office System
- Vuln IDs
-
- V-26629
- Rule IDs
-
- SV-34085r1_rule
Checks: C-34225r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing “Key Usage Filtering” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\general Criteria: If the value FilterDigitalSignatureCert is REG_DWORD = 1, this is not a finding.
Fix: F-29915r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Signing “Key Usage Filtering” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO345 - Office System
- Vuln IDs
-
- V-26630
- Rule IDs
-
- SV-34086r1_rule
Checks: C-34226r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools | Options | General | Service Options... -> Online Content “Online content options” must be set to “Enabled: Search only offline content whenever available”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value UseOnlineContent is REG_DWORD = 1, this is not a finding.
Fix: F-29916r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools | Options | General | Service Options... -> Online Content “Online content options” to “Enabled: Search only offline content whenever available”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO312 - Office System
- Vuln IDs
-
- V-26631
- Rule IDs
-
- SV-34087r1_rule
Checks: C-34227r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools | Options | General | Web Options... “Disable customer-submitted templates downloads from Office.com” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value DisableCustomerSubmittedDownload is REG_DWORD = 1, this is not a finding.
Fix: F-29917r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools | Options | General | Web Options... “Disable customer-submitted templates downloads from Office.com” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO321 - Office System
- Vuln IDs
-
- V-26704
- Rule IDs
-
- SV-34089r1_rule
Checks: C-34449r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Encrypt document properties” must be set to “Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value EncryptDocProps is REG_DWORD = 1, this is not a finding.
Fix: F-30018r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Encrypt document properties” to “Enabled".