Skip to content

III - Administrative Public

Rules and Groups employed by this XCCDF Profile

  • DTOO193 - Automation Security

    Group
  • Automation Security to enforce macro level security in Office documents must be configured.

    When a separate program is used to launch Microsoft Office Excel, PowerPoint, or Word programmatically, any macros can run in the programmatically opened application without being blocked. This fun...
    Rule Medium Severity
  • DTOO203 - Legacy Format signatures

    Group
  • Legacy format signatures must be enabled.

    Office applications use the XML–based XMLDSIG format to attach digital signatures to documents, including Office 97-2003 binary documents. XMLDSIG signatures are not recognized by Office 2003 appli...
    Rule Medium Severity
  • DTOO192 - Load controls for forms3

    Group
  • Load controls in forms3 must be disabled from loading.

    ActiveX controls are Component Object Model (COM) objects and have unrestricted access to users' computers. ActiveX controls can access the local file system and change the registry settings of the...
    Rule Medium Severity
  • DTOO179 - Open as Read/Write when browsing

    Group
  • Documents must be configured to not open as Read Write when browsing.

    Office document on a Web server using Internet Explorer, the appropriate application opens the file in read-only mode. However, if the default configuration is changed, the document is opened as re...
    Rule Medium Severity
  • DTOO199 - Permissions on managed content

    Group
  • Changing permissions on rights managed content for users must be enforced.

    This setting controls whether Office 2010 users can change permissions for content that is protected with Information Rights Management (IRM). The Information Rights Management feature of Office ...
    Rule Medium Severity
  • DTOO178 - Uploads to Office Online

    Group
  • Upload of document templates to Office Online must be prevented.

    Office users can share Excel, PowerPoint, and Word templates they create with other Microsoft Office users around the world by uploading them to the community area of the Microsoft Office Online We...
    Rule Medium Severity
  • DTOO188 - Protect document metadata

    Group
  • Document metadata for password protected files must be protected.

    When an Office Open XML document is protected with a password and saved, any metadata associated with the document is encrypted along with the rest of the document's contents. If this configuration...
    Rule Medium Severity
  • DTOO187 - Protect metadata / rights managed docs

    Group
  • Rights managed Office Open XML files must be protected.

    When Information Rights Management (IRM) is used to restrict access to an Office Open XML document, any metadata associated with the document is not encrypted. This configuration could allow potent...
    Rule Medium Severity
  • DTOO180 - Vector Markup Lang (VML) / IE graphics

    Group
  • Vector markup Language (VML) for displaying graphics in browsers must be disallowed.

    When saving documents as Web pages, Excel, PowerPoint, and Word can save vector–based graphics in Vector Markup Language (VML), which enables Internet Explorer to display them smoothly at any resol...
    Rule Medium Severity
  • DTOO204 - External Signature Services menu

    Group
  • External Signature Services Menu for Office must be suppressed.

    Users can select Add Signature Services (from the Signature Line drop-down menu on the Insert tab of the Ribbon in Excel 2010, PowerPoint 2010, and Word 2010) to see a list of signature service pro...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules