Microsoft Office System 2016 Security Technical Implementation Guide

Overview

VersionDateFinding Count (20)Downloads
22024-12-06CAT I (High): 0CAT II (Medium): 20CAT III (Low): 0
STIG Description
This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DOD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.
ClassifiedPublicSensitive
I - Mission Critical ClassifiedI - Mission Critical PublicI - Mission Critical Sensitive
II - Mission Support ClassifiedII - Mission Support PublicII - Mission Support Sensitive
III - Administrative ClassifiedIII - Administrative PublicIII - Administrative Sensitive

Findings - MAC III - Administrative Public

Finding IDSeverityTitleDescription
V-238024
LOWMEDIUMHIGH
The Help Improve Proofing Tools feature for Office must be configured.This policy setting controls whether the Help Improve Proofing Tools feature sends usage data to Microsoft. The Help Improve Proofing Tools feature co...
V-238025
LOWMEDIUMHIGH
Trust Bar notifications for Security messages must be enforced.This policy setting controls whether Office 2016 applications notify users when potentially unsafe features or content are detected, or whether such f...
V-238026
LOWMEDIUMHIGH
Rights managed Office Open XML files must be protected.This policy setting determines whether metadata is encrypted in Office Open XML files that are protected by Information Rights Management (IRM). If yo...
V-238027
LOWMEDIUMHIGH
Document metadata for password protected files must be protected.This policy setting determines whether metadata is encrypted when an Office Open XML file is password protected. If you enable this policy setting, Ex...
V-238028
LOWMEDIUMHIGH
The encryption type for password protected Open XML files must be set.This policy setting allows you to specify an encryption type for Office Open XML files. If you enable this policy setting, you can specify the type of...
V-238029
LOWMEDIUMHIGH
The encryption type for password protected Office 97 thru Office 2003 must be set.This policy setting enables you to specify an encryption type for password-protected Office 97-2003 files. If you enable this policy setting, you can ...
V-238030
LOWMEDIUMHIGH
ActiveX control initialization must be disabled.This policy setting specifies the Microsoft ActiveX« initialization security level for all Microsoft Office applications. ActiveX controls can adverse...
V-238031
LOWMEDIUMHIGH
Load controls in forms3 must be disabled from loading.This policy setting allows you to control how ActiveX controls in UserForms should be initialized based upon whether they are Safe For Initialization ...
V-238032
LOWMEDIUMHIGH
Automation Security to enforce macro level security in Office documents must be configured.This policy setting controls whether macros can run in an Office 2016 application that is opened programmatically by another application. If you enabl...
V-238033
LOWMEDIUMHIGH
A mix of policy and user locations for Office Products must be disallowed.This policy setting controls whether trusted locations can be defined by users, the Office Customization Tool (OCT), and Group Policy, or if they must...
V-238034
LOWMEDIUMHIGH
Smart Documents use of Manifests in Office must be disallowed.This policy setting controls whether Office 2016 applications can load an XML expansion pack manifest file with a Smart Document. An XML expansion pac...
V-238035
LOWMEDIUMHIGH
Connection verification of permissions must be enforced.This policy setting controls whether users are required to connect to the Internet or a local network to have their licenses confirmed every time they...
V-238036
LOWMEDIUMHIGH
Inclusion of document properties for PDF and XPS output must be disallowed.This policy setting controls whether document metadata can be saved in PDF and XPS documents. If you enable this policy setting, document properties m...
V-238037
LOWMEDIUMHIGH
Encrypt document properties must be configured for OLE documents.This policy setting allows you configure if the document properties are encrypted. This applies to OLE documents (Office 97-2003 compatible) if the a...
V-238038
LOWMEDIUMHIGH
Office Presentation Service must be removed as an option for presenting PowerPoint and Word online.This policy setting allows you to remove Office Presentation Service from the list of online presentation services in PowerPoint and Word. This list a...
V-238039
LOWMEDIUMHIGH
The ability to create an online presentation programmatically must be disabled.This policy setting allows you to restrict the ability to create an online presentation programmatically in PowerPoint and Word. If you enable this po...
V-238040
LOWMEDIUMHIGH
When using the Office Feedback tool, the ability to include a screenshot must be disabled.This policy setting manages whether the Office Feedback Tool (a.k.a. Send a Smile) allows the user to send a screenshot of their desktop with their fe...
V-238041
LOWMEDIUMHIGH
The ability to run unsecure Office web add-ins and Catalogs must be disabled.This policy setting allows users to run unsecure web add-in, which are add-ins that have web page or catalog locations that are not SSL-secured (https...
V-238042
LOWMEDIUMHIGH
The Office Telemetry Agent must be configured to obfuscate the file name, file path, and title of Office documents before uploading telemetry data to the shared folder.This policy setting configures Office Telemetry Agent to disguise, or obfuscate, certain file properties that are reported in telemetry data. If this ...
V-238043
LOWMEDIUMHIGH
The ability to send personal information to Office must be disabled.This policy setting controls whether users can send personal information to Office. When users choose to send information Office 2016 applications aut...