Skip to content

Microsoft Publisher 2013 STIG

Rules, Groups, and Values defined within the XCCDF Benchmark

  • DTOO322 - Prompt files to open instead of blocking

    Group
  • Fatally corrupt files must be blocked from opening.

    Enabling this setting allows a user to open fatally corrupt Publisher 2013 files. As a result, malicious code or users could become active on the user's computer or the network. For example, a ma...
    Rule Medium Severity
  • DTOO323 - Publisher Automation Security Level

    Group
  • The Publisher Automation Security Level must be configured for high security.

    When a separate application is used to launch Publisher 2013 programmatically, any macros can run in the programmatically-opened application without being blocked. Disabling or not configuring thi...
    Rule Medium Severity
  • DTOO111 - Enable IE Bind to Object

    Group
  • DTOO117 - Saved from URL

    Group
  • DTOO123 - Block Navigation to URL from Office

    Group
  • Navigation to URLs embedded in Office products must be blocked.

    To protect users from attacks, Internet Explorer usually does not attempt to load malformed URLs. This functionality can be controlled separately for instances of Internet Explorer spawned by Offic...
    Rule Medium Severity
  • DTOO124 - Scripted Window Security

    Group
  • Scripted Window Security must be enforced.

    Malicious websites often try to confuse or trick users into giving a site permission to perform an action allowing the site to take control of the users' computer in some manner. Disabling or not c...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules