2.29.2 Ensure 'Legacy Format Signatures' is set to Disabled

Information

This policy setting controls whether users can apply binary format digital signatures to Office 97-2003 documents. The recommended state for this setting is: Disabled. By default, Office applications use the XML-based XMLDSIG format to attach digital signatures to documents, including Office 97-2003 binary documents. XMLDSIG signatures are not recognized by Office 2003 applications or previous versions. If an Office 2003 user opens an Excel, PowerPoint, or Word binary document with an XMLDSIG signature attached, the signature will be lost.

Solution

To implement the recommended configuration state, set the following Group Policy setting to Disabled. User Configuration\Administrative Templates\Microsoft Office 2016\Signing\Legacy Format Signatures Impact: Enabling this setting is not likely to cause significant usability issues for most Office users.

See Also

https://workbench.cisecurity.org/files/571

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-7(6)

Plugin: Windows

Control ID: 542945145e99889ee0f4c45a5d01a78da2bbb991919598b7d5073bd16d1c94f5