2.3.27.17 (L1) Ensure 'Protect document metadata for password protected files' is set to 'Enabled'

Information

This policy setting determines whether metadata is encrypted when an Office Open XML file is password protected.

The recommended state for this setting is: Enabled

By default, when an Office Open XML document is protected with a password and saved, any metadata associated with the document is encrypted along with the rest of the document's contents. If this configuration is changed, potentially sensitive information such as the document author and hyperlink references could be exposed to unauthorized people.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled :

Microsoft Office 2016\Security Settings\Protect document metadata for password protected files

Impact:

Enabling this setting might interfere with the functioning of tools that aggregate and display metadata information for Office Open XML file but is otherwise unlikely to cause significant usability issues.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|IA-5(1), 800-53|SC-28, 800-53|SC-28(1)

Plugin: Windows

Control ID: ff81e37a40a75dfdc0c8457e9069b877bee89c6e92af0e4a45727db303dc39fa