Skip to content

Microsoft Office System 2016 Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Encrypt document properties must be configured for OLE documents.

    This policy setting allows you configure if the document properties are encrypted. This applies to OLE documents (Office 97-2003 compatible) if the application is configured for CAPI RC4. If you e...
    Rule Medium Severity
  • SRG-APP-000141

    Group
  • SRG-APP-000210

    Group
  • The ability to create an online presentation programmatically must be disabled.

    This policy setting allows you to restrict the ability to create an online presentation programmatically in PowerPoint and Word. If you enable this policy setting, an online presentation cannot be ...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • SRG-APP-000516

    Group
  • The ability to run unsecure Office web add-ins and Catalogs must be disabled.

    This policy setting allows users to run unsecure web add-in, which are add-ins that have web page or catalog locations that are not SSL-secured (https://), and are not in users' Internet zones. If ...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The Office Telemetry Agent must be configured to obfuscate the file name, file path, and title of Office documents before uploading telemetry data to the shared folder.

    This policy setting configures Office Telemetry Agent to disguise, or obfuscate, certain file properties that are reported in telemetry data. If this policy setting is enabled, Office Telemetry Age...
    Rule Medium Severity
  • SRG-APP-000516

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules