Microsoft Office System 2010 STIG
Rules, Groups, and Values defined within the XCCDF Benchmark
-
DTOO203 - Legacy Format signatures
Group -
DTOO192 - Load controls for forms3
Group -
DTOO179 - Open as Read/Write when browsing
Group -
Documents must be configured to not open as Read Write when browsing.
Office document on a Web server using Internet Explorer, the appropriate application opens the file in read-only mode. However, if the default configuration is changed, the document is opened as re...Rule Medium Severity -
DTOO199 - Permissions on managed content
Group -
DTOO178 - Uploads to Office Online
Group -
Upload of document templates to Office Online must be prevented.
Office users can share Excel, PowerPoint, and Word templates they create with other Microsoft Office users around the world by uploading them to the community area of the Microsoft Office Online We...Rule Medium Severity -
DTOO188 - Protect document metadata
Group -
DTOO187 - Protect metadata / rights managed docs
Group -
Rights managed Office Open XML files must be protected.
When Information Rights Management (IRM) is used to restrict access to an Office Open XML document, any metadata associated with the document is not encrypted. This configuration could allow potent...Rule Medium Severity -
DTOO180 - Vector Markup Lang (VML) / IE graphics
Group -
DTOO204 - External Signature Services menu
Group -
External Signature Services Menu for Office must be suppressed.
Users can select Add Signature Services (from the Signature Line drop-down menu on the Insert tab of the Ribbon in Excel 2010, PowerPoint 2010, and Word 2010) to see a list of signature service pro...Rule Medium Severity -
DTOO306 - Disable hyperlinks to web templates
Group -
Hyperlinks to web templates in File | New and task panes must be disabled.
This setting controls whether users can follow hyperlinks to templates on Office.com from within Office 2010 applications.Rule Medium Severity -
DTOO307 - Office Live Workspace Integration
Group -
Office Live Workspace Integration must be off.
This setting controls the exposing of entry points for Office Live Workspace Integration features.Rule Medium Severity -
DTOO311 - Key Usage Filtering
Group -
DTOO345 - Online content options
Group -
Online content options must be configured for offline content availability.
The Office 2010 Help system automatically searches Microsoft Office.com for content when a computer is connected to the Internet. Users can change this default by clearing the Search Microsoft Off...Rule Medium Severity -
DTOO312 - Customer-submitted templates downloads
Group -
Customer-submitted templates downloads from Office.com must be disallowed.
This policy setting controls whether Office 2010 users can download templates from the community area of Office.com by clicking New on the Microsoft Office menu. If you enable this policy setting, ...Rule Medium Severity -
DTOO321 - Encrypt document properties
Group -
Encrypt document properties must be configured for OLE documents.
This policy setting allows you configure if the document properties are encrypted. This applies to OLE documents (Office 97-2003 compatible) if the application is configured for CAPI RC4. Disabli...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.