Skip to content

I - Mission Critical Classified

Rules and Groups employed by this XCCDF Profile

  • DTOO178 - Uploads to Office Online

    <GroupDescription></GroupDescription>
    Group
  • Upload of document templates to Office Online must be prevented.

    &lt;VulnDiscussion&gt;Office users can share Excel, PowerPoint, and Word templates they create with other Microsoft Office users around the world b...
    Rule Medium Severity
  • DTOO188 - Protect document metadata

    <GroupDescription></GroupDescription>
    Group
  • Document metadata for password protected files must be protected.

    &lt;VulnDiscussion&gt;When an Office Open XML document is protected with a password and saved, any metadata associated with the document is encrypt...
    Rule Medium Severity
  • DTOO187 - Protect metadata / rights managed docs

    <GroupDescription></GroupDescription>
    Group
  • Rights managed Office Open XML files must be protected.

    &lt;VulnDiscussion&gt;When Information Rights Management (IRM) is used to restrict access to an Office Open XML document, any metadata associated w...
    Rule Medium Severity
  • DTOO180 - Vector Markup Lang (VML) / IE graphics

    <GroupDescription></GroupDescription>
    Group
  • Vector markup Language (VML) for displaying graphics in browsers must be disallowed.

    &lt;VulnDiscussion&gt;When saving documents as Web pages, Excel, PowerPoint, and Word can save vector–based graphics in Vector Markup Language (VML...
    Rule Medium Severity
  • DTOO204 - External Signature Services menu

    <GroupDescription></GroupDescription>
    Group
  • External Signature Services Menu for Office must be suppressed.

    &lt;VulnDiscussion&gt;Users can select Add Signature Services (from the Signature Line drop-down menu on the Insert tab of the Ribbon in Excel 2010...
    Rule Medium Severity
  • DTOO306 - Disable hyperlinks to web templates

    <GroupDescription></GroupDescription>
    Group
  • Hyperlinks to web templates in File | New and task panes must be disabled.

    &lt;VulnDiscussion&gt;This setting controls whether users can follow hyperlinks to templates on Office.com from within Office 2010 applications. &...
    Rule Medium Severity
  • DTOO307 - Office Live Workspace Integration

    <GroupDescription></GroupDescription>
    Group
  • Office Live Workspace Integration must be off.

    &lt;VulnDiscussion&gt;This setting controls the exposing of entry points for Office Live Workspace Integration features. &lt;/VulnDiscussion&gt;&l...
    Rule Medium Severity
  • DTOO311 - Key Usage Filtering

    <GroupDescription></GroupDescription>
    Group
  • Key Usage Filtering must be allowed.

    &lt;VulnDiscussion&gt;This policy setting allows you to filter a list of digital certificates for signing Excel, PowerPoint, and Word documents, ba...
    Rule Medium Severity
  • DTOO345 - Online content options

    <GroupDescription></GroupDescription>
    Group
  • Online content options must be configured for offline content availability.

    &lt;VulnDiscussion&gt;The Office 2010 Help system automatically searches Microsoft Office.com for content when a computer is connected to the Inter...
    Rule Medium Severity
  • DTOO312 - Customer-submitted templates downloads

    <GroupDescription></GroupDescription>
    Group
  • Customer-submitted templates downloads from Office.com must be disallowed.

    &lt;VulnDiscussion&gt;This policy setting controls whether Office 2010 users can download templates from the community area of Office.com by clicki...
    Rule Medium Severity
  • DTOO321 - Encrypt document properties

    <GroupDescription></GroupDescription>
    Group
  • Encrypt document properties must be configured for OLE documents.

    &lt;VulnDiscussion&gt;This policy setting allows you configure if the document properties are encrypted. This applies to OLE documents (Office 97-...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules