Microsoft Excel 2013 STIG
Rules, Groups, and Values defined within the XCCDF Benchmark
-
Open/Save actions for Excel 3 worksheets must be blocked.
This setting specifies whether users can open, view, edit, or save files saved in the specified format. Enabling block of the specified format mitigates zero-day security attacks (which are attacks...Rule Medium Severity -
Actions for Excel 95 workbooks must be configured to edit in Protected View.
This setting specifies whether users can open, view, edit, or save files saved in the specified format. Enabling block of the specified format mitigates zero-day security attacks (which are attacks...Rule Medium Severity -
Actions for Excel 95-97 workbooks and templates must be configured to edit in Protected View.
This setting specifies whether users can open, view, edit, or save files saved in the specified format. Enabling block of the specified format mitigates zero-day security attacks (which are attacks...Rule Medium Severity -
Excel attachments opened from Outlook must be in Protected View.
This policy setting allows for determining whether Excel files in Outlook attachments open in Protected View. If enabling this policy setting, Outlook attachments do not open in Protected View. If ...Rule Medium Severity -
WEBSERVICE functions must be disabled.
The WEBSERVICE function option, when used in an Excel spreadsheet, returns data from a web service on the Internet or Intranet. If allowed to be used, security is significantly reduced by allowing ...Rule Medium Severity -
Macros must be blocked from running in Office 2013 files from the Internet.
This policy setting allows you to block macros from running in Office files that come from the Internet. If you enable this policy setting, macros are blocked from running, even if "Enable all macr...Rule Medium Severity -
The opening of pre-release versions of file formats new to Excel 2013 through the Compatibility Pack for Office 2013 and Excel 2013 Converter must be blocked.
By default, users are prompted to update automatic links.Rule Medium Severity -
DTOO117 - Saved from URL
Group -
DTOO123-Block Navigation to URL from Office
Group -
DTOO129 - Block Pop-Ups
Group -
DTOO131 - Trust Bar Notifications
Group -
DTOO210 - Block opening of pre-release versions
Group -
DTOO142 - Force Scan Encr. Macros in open XML
Group -
DTOO134 - Trusted locations on computer
Group -
DTOO139 - Save files default format
Group -
DTOO146-Disable Trust access to VB Project Macros
Group -
DTOO304 - VBA Macro Warning settings
Group -
DTOO143 - Force File Extension to match type
Group -
File types must be configured to provide mismatch warnings
Excel can load files with extensions that do not match the files' type. For example, if a comma-separated values (CSV) file named example.csv is renamed example.xls, Excel can properly load it as a...Rule Medium Severity -
DTOO138 - Internet and Network Path hyperlinks
Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.