Skip to content

Microsoft Excel 2013 STIG

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Open/Save actions for Excel 3 worksheets must be blocked.

    This setting specifies whether users can open, view, edit, or save files saved in the specified format. Enabling block of the specified format mitigates zero-day security attacks (which are attacks...
    Rule Medium Severity
  • Actions for Excel 95 workbooks must be configured to edit in Protected View.

    This setting specifies whether users can open, view, edit, or save files saved in the specified format. Enabling block of the specified format mitigates zero-day security attacks (which are attacks...
    Rule Medium Severity
  • Actions for Excel 95-97 workbooks and templates must be configured to edit in Protected View.

    This setting specifies whether users can open, view, edit, or save files saved in the specified format. Enabling block of the specified format mitigates zero-day security attacks (which are attacks...
    Rule Medium Severity
  • Excel attachments opened from Outlook must be in Protected View.

    This policy setting allows for determining whether Excel files in Outlook attachments open in Protected View. If enabling this policy setting, Outlook attachments do not open in Protected View. If ...
    Rule Medium Severity
  • WEBSERVICE functions must be disabled.

    The WEBSERVICE function option, when used in an Excel spreadsheet, returns data from a web service on the Internet or Intranet. If allowed to be used, security is significantly reduced by allowing ...
    Rule Medium Severity
  • Macros must be blocked from running in Office 2013 files from the Internet.

    This policy setting allows you to block macros from running in Office files that come from the Internet. If you enable this policy setting, macros are blocked from running, even if "Enable all macr...
    Rule Medium Severity
  • The opening of pre-release versions of file formats new to Excel 2013 through the Compatibility Pack for Office 2013 and Excel 2013 Converter must be blocked.

    By default, users are prompted to update automatic links.
    Rule Medium Severity
  • DTOO117 - Saved from URL

    Group
  • DTOO123-Block Navigation to URL from Office

    Group
  • DTOO129 - Block Pop-Ups

    Group
  • DTOO131 - Trust Bar Notifications

    Group
  • DTOO210 - Block opening of pre-release versions

    Group
  • DTOO142 - Force Scan Encr. Macros in open XML

    Group
  • DTOO134 - Trusted locations on computer

    Group
  • DTOO139 - Save files default format

    Group
  • DTOO146-Disable Trust access to VB Project Macros

    Group
  • DTOO304 - VBA Macro Warning settings

    Group
  • DTOO143 - Force File Extension to match type

    Group
  • File types must be configured to provide mismatch warnings

    Excel can load files with extensions that do not match the files' type. For example, if a comma-separated values (CSV) file named example.csv is renamed example.xls, Excel can properly load it as a...
    Rule Medium Severity
  • DTOO138 - Internet and Network Path hyperlinks

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules