II - Mission Support Classified
Rules and Groups employed by this XCCDF Profile
-
SRG-APP-000516
Group -
The Help Improve Proofing Tools feature for Office must be configured.
The "Help Improve Proofing Tools" feature collects data about use of the Proofing Tools, such as additions to the custom dictionary, and sends it to Microsoft. After about six months, the feature s...Rule Medium Severity -
SRG-APP-000516
Group -
A mix of policy and user locations for Office Products must be disallowed.
When Microsoft Office files are opened from trusted locations, all the content in the files is enabled and active. Users are not notified about any potential risks that might be contained in the fi...Rule Medium Severity -
SRG-APP-000516
Group -
Smart Documents use of Manifests in Office must be disallowed.
An XML expansion pack is the group of files that constitutes a Smart Document in Excel and Word. One or more components that provide the logic needed for a Smart Document are packaged by using an X...Rule Medium Severity -
SRG-APP-000516
Group -
Legacy format signatures must be enabled.
Office applications use the XML-based XMLDSIG format to attach digital signatures to documents, including Office 97-2003 binary documents. XMLDSIG signatures are not recognized by Office 2003 appli...Rule Medium Severity -
SRG-APP-000516
Group -
External Signature Services Menu for Office must be suppressed.
Users can select Add Signature Services (from the Signature Line drop-down menu on the Insert tab of the Ribbon in Excel 2013, PowerPoint 2013, and Word 2013) to see a list of signature service pro...Rule Medium Severity -
SRG-APP-000516
Group -
Inclusion of document properties for PDF and XPS output must be disallowed.
If the Microsoft Save as PDF or XPS Add-in for Microsoft Office Programs is installed, document properties are saved as metadata when users save or publish files using the PDF or XPS commands in Ac...Rule Medium Severity -
SRG-APP-000516
Group -
Blogging entries created from inside Office products must be configured for SharePoint only.
The blogging feature in Office products enables users to compose blog entries and post them to their blogs directly from Office, without using any additional software. By default, users can post bl...Rule Medium Severity -
SRG-APP-000516
Group -
The Enable Updates and Disable Updates options in the UI must be hidden from users.
This policy setting allows the user interface (UI) options to enable or disable Office automatic updates to be hidden from users. These options are found in the Product Information area of all Offi...Rule Medium Severity -
SRG-APP-000516
Group -
When using the Office Feedback tool, the ability to include a screenshot must be disabled.
The "Office Feedback" tool, also called "Send-a-Smile", allows a user to click on an icon and send feedback to Microsoft. The "Office Feedback" Tool must be configured to be disabled. In the event ...Rule Medium Severity -
SRG-APP-000516
Group -
The ability to run unsecure Office apps must be disabled.
Unsecure apps for Office, which are apps that have web page or catalog locations that are not SSL-secured (https://), and/or are not in users' Internet zones may allow data to be transmitted/access...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.