III - Administrative Public
Rules and Groups employed by this XCCDF Profile
-
DTOO193 - Automation Security
Group -
Automation Security to enforce macro level security in Office documents must be configured.
When a separate program is used to launch Microsoft Office Excel, PowerPoint, or Word programmatically, any macros can run in the programmatically opened application without being blocked. This fun...Rule Medium Severity -
DTOO203 - Legacy Format signatures
Group -
Legacy format signatures must be enabled.
Office applications use the XML–based XMLDSIG format to attach digital signatures to documents, including Office 97-2003 binary documents. XMLDSIG signatures are not recognized by Office 2003 appli...Rule Medium Severity -
DTOO192 - Load controls for forms3
Group -
Load controls in forms3 must be disabled from loading.
ActiveX controls are Component Object Model (COM) objects and have unrestricted access to users' computers. ActiveX controls can access the local file system and change the registry settings of the...Rule Medium Severity -
DTOO179 - Open as Read/Write when browsing
Group -
Documents must be configured to not open as Read Write when browsing.
Office document on a Web server using Internet Explorer, the appropriate application opens the file in read-only mode. However, if the default configuration is changed, the document is opened as re...Rule Medium Severity -
DTOO199 - Permissions on managed content
Group -
Changing permissions on rights managed content for users must be enforced.
This setting controls whether Office 2010 users can change permissions for content that is protected with Information Rights Management (IRM). The Information Rights Management feature of Office ...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.