2.3.37.3.1 (L1) Ensure 'Open Office documents as read/write while browsing' is set to 'Disabled'

Information

This policy setting controls whether users can edit and save Office documents on Web servers that they have opened using Internet Explorer.

The recommended state for this setting is: Disabled

By default, when users browse to an Office document on a Web server using Internet Explorer, the appropriate application opens the file in read-only mode. However, if the default configuration is changed, the document is opened as read/write. Users could potentially make changes to documents and overwrite them in situations where the Web server security is not configured to prevent such changes.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Disabled :

Microsoft Office 2016\Tools | Options | General | Web Options...\Files\Open Office Documents as Read/Write While Browsing

Impact:

This setting enforces the Office default configuration and therefore should have minimal impact on users.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|CM-11, 800-53|SC-18

Plugin: Windows

Control ID: 3c181b1c25761f020503bac0b0910c8daa9bcf79810d0258c5ae894ae912d124