DISA STIG Microsoft Office System 2016 v1r1

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: DISA STIG Microsoft Office System 2016 v1r1

Updated: 10/5/2021

Authority: DISA STIG

Plugin: Windows

Revision: 1.11

Audit Changelog

 
Revision 1.11

Oct 5, 2021

Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • References updated.
Revision 1.10

Jul 30, 2021

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.9

Jun 17, 2021

Miscellaneous
  • Metadata updated.
Revision 1.8

Feb 1, 2021

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.7

Sep 29, 2020

Miscellaneous
  • References updated.
Revision 1.6

Apr 22, 2020

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.5

Feb 11, 2019

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.4

Dec 14, 2018

Miscellaneous
  • References updated.
Revision 1.3

Jul 24, 2018

Miscellaneous
  • Metadata updated.
  • Platform check updated.
Added
  • DTOO182 - The Help Improve Proofing Tools feature for Office must be configured
  • DTOO186 - Trust Bar notifications for Security messages must be enforced
  • DTOO187 - Rights managed Office Open XML files must be protected
  • DTOO188 - Document metadata for password protected files must be protected
  • DTOO189 - The encryption type for password protected Open XML files must be set.
  • DTOO190 - The encryption type for password protected Office 97 thru Office 2003 must be set
  • DTOO191 - ActiveX control initialization must be disabled
  • DTOO192 - Load controls in forms3 must be disabled from loading
  • DTOO193 - Automation Security to enforce macro level security in Office documents must be configured
  • DTOO196 - A mix of policy and user locations for Office Products must be disallowed
  • DTOO197 - Smart Documents use of Manifests in Office must be disallowed
  • DTOO201 - Connection verification of permissions must be enforced
  • DTOO206 - Inclusion of document properties for PDF and XPS output must be disallowed
  • DTOO321 - Encrypt document properties must be configured for OLE documents
  • DTOO408 - Office Presentation Service must be removed as an option for presenting PowerPoint and Word online
  • DTOO409 - The ability to create an online presentation programmatically must be disable
  • DTOO410 - When using the Office Feedback tool, the ability to include a screenshot must be disabled
  • DTOO412 - The ability to run unsecure Office web add-ins and Catalogs must be disabled
  • DTOO416 - The Office Telemetry Agent must be configured to obfuscate the file name, file path, and title of Office documents
  • DTOO601 - The ability to send personal information to Office must be disabled
Removed
  • DTOO182 - The Help Improve Proofing Tools feature for Office must be configured
  • DTOO186 - Trust Bar notifications for Security messages must be enforced
  • DTOO187 - Rights managed Office Open XML files must be protected
  • DTOO188 - Document metadata for password protected files must be protected
  • DTOO189 - The encryption type for password protected Open XML files must be set.
  • DTOO190 - The encryption type for password protected Office 97 thru Office 2003 must be set
  • DTOO191 - ActiveX control initialization must be disabled
  • DTOO192 - Load controls in forms3 must be disabled from loading
  • DTOO193 - Automation Security to enforce macro level security in Office documents must be configured
  • DTOO196 - A mix of policy and user locations for Office Products must be disallowed
  • DTOO197 - Smart Documents use of Manifests in Office must be disallowed
  • DTOO201 - Connection verification of permissions must be enforced
  • DTOO206 - Inclusion of document properties for PDF and XPS output must be disallowed
  • DTOO321 - Encrypt document properties must be configured for OLE documents
  • DTOO408 - Office Presentation Service must be removed as an option for presenting PowerPoint and Word online
  • DTOO409 - The ability to create an online presentation programmatically must be disable
  • DTOO410 - When using the Office Feedback tool, the ability to include a screenshot must be disabled
  • DTOO412 - The ability to run unsecure Office web add-ins and Catalogs must be disabled
  • DTOO416 - The Office Telemetry Agent must be configured to obfuscate the file name, file path, and title of Office documents
  • DTOO601 - The ability to send personal information to Office must be disabled
  • Microsoft Office 2016 is not installed or remote registry service is disabled.