II - Mission Support Public
Rules and Groups employed by this XCCDF Profile
-
DTOO196 - Mix of Policy and User Locations
<GroupDescription></GroupDescription>Group -
A mix of policy and user locations for Office Products must be disallowed.
<VulnDiscussion>When Microsoft Office files are opened from trusted locations, all the content in the files is enabled and active. Users are ...Rule Medium Severity -
DTOO212 - Control Blogging
<GroupDescription></GroupDescription>Group -
Blogging entries created from inside Office products must be configured for Sharepoint only.
<VulnDiscussion>The blogging feature in Office products enables users to compose blog entries and post them to their blogs directly from Offi...Rule Medium Severity -
DTOO200 - Allow users to read with browsers
<GroupDescription></GroupDescription>Group -
Office must be configured to not allow read with browsers.
<VulnDiscussion>The Windows Rights Management Add-on for Internet Explorer provides a way for users who do not use the 2010 Office release to...Rule Medium Severity -
DTOO177-Disable Updates from Office Online Site
<GroupDescription></GroupDescription>Group -
Access to updates, add-ins, and patches on Office.com must be disabled.
<VulnDiscussion>Having access to updates, add-ins, and patches on the Office Online Web site can help users ensure computers are up to date a...Rule Medium Severity -
DTOO186 - Trust Bar Notifications
<GroupDescription></GroupDescription>Group -
Trust Bar notifications for Security messages must be enforced.
<VulnDiscussion>The Message Bar in Office applications is used to identify security issues, such as unsigned macros or potentially unsafe add...Rule Medium Severity -
DTOO207 - Document Info Beaconing UI
<GroupDescription></GroupDescription>Group -
Document Information panel Beaconing must show UI.
<VulnDiscussion>For controlling whether users see a security warning when they open custom Document Information Panels that contain a Web bea...Rule Medium Severity -
DTOO184 - Cust. Experience Improvement Program
<GroupDescription></GroupDescription>Group -
The Customer Experience Improvement Program for Office must be disabled.
<VulnDiscussion>When users choose to participate in the Customer Experience Improvement Program (CEIP), Office applications automatically sen...Rule Medium Severity -
DTOO190 - Encr. type for Password Protected files
<GroupDescription></GroupDescription>Group -
The encryption type for password protected Office 97 thru Office 2003 must be set.
<VulnDiscussion>If unencrypted files are intercepted, sensitive information in the files can be compromised. To protect information confident...Rule Medium Severity -
DTOO189 - Encryption Type for Pwd Protected files
<GroupDescription></GroupDescription>Group -
The encryption type for password protected Open XML files must be set.
<VulnDiscussion>If unencrypted files are intercepted, sensitive information in the files can be compromised. To protect information confident...Rule Medium Severity -
DTOO182 - Improve Proofing Tools
<GroupDescription></GroupDescription>Group -
The Help Improve Proofing Tools feature for Office must be configured.
<VulnDiscussion>The Help Improve Proofing Tools feature collects data about use of the Proofing Tools, such as additions to the custom dictio...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.