1.8.7.2.1.1 Ensure 'Default File Block Behavior' is set to Enabled (Blocked files are not opened)

Information

This policy setting allows you to determine if users can open, view, or edit Word files. If you enable this policy setting, you can set one of these options: - Blocked files are not opened - Blocked files open in Protected View and cannot be edited - Blocked files open in Protected View and can be edited If you disable or do not configure this policy setting, the behavior is the same as the 'Blocked files are not opened' setting. Users will not be able to open blocked files. The recommended state for this setting is: Enabled. By default, users can open, view, or edit a large number of file types in Word. Some file types are safer than others, as some could allow malicious code to become active on user computers or the network. For this reason, disabling or not configuring this setting could allow malicious code to become active on user computers or the network.

Solution

To implement the recommended configuration state, set the following Group Policy setting to Enabled. User Configuration\Administrative Templates\Microsoft Word 2013\Word Options\Security\Trust Center\File Block Settings\Set Default File Block Behavior Impact: Enabling this setting prevents users from opening, viewing, or editing certain types of files in Word. Productivity in your organization could be affected if users who require access to any of these file types cannot access them.

See Also

https://workbench.cisecurity.org/files/556

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3c.2.

Plugin: Windows

Control ID: 7721387270701f0d566bd7dff569c8cdaa384e1f19b4a1a3a682d3b59a92ccb7