2.25.9 Ensure 'Encryption Type for Password Protected Office 97-2003 files' is set to Enabled

Information

This policy setting enables you to specify an encryption type for password-protected Office 97-2003 files. The recommended state for this setting is: Enabled. If unencrypted files are intercepted, sensitive information in the files can be compromised. To protect information confidentiality, Microsoft Office application files can be encrypted and password protected. Only users who know the correct password will be able to decrypt such files. By default, Excel, PowerPoint, and Word use Office 97/2000 Compatible encryption, a proprietary encryption method, to encrypt password-protected Office 97-2003 files.

Solution

To implement the recommended configuration state, set the following Group Policy setting to Enabled. User Configuration\Administrative Templates\Microsoft Office 2016\Security Settings\Encryption Type for Password Protected Office 97-2003 files Impact: Consider the needs of your organization and users when selecting an encryption method to enforce. If you work for a government agency, contract for a government agency, or otherwise work with very sensitive information, you might need to select a method that complies with policies that govern how such information is processed. Remember that you will need to ensure that the selected cryptographic service provider is installed on the computers of all users who need to work with password-protected Office 97-2003 files.

See Also

https://workbench.cisecurity.org/files/571

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Windows

Control ID: fea961636bb621f0909c31b69d4d8588127abfcb9b89425250d256e8b24c0040