2.11.8.7.2.1.5 (L1) Ensure 'Word 2007 and later binary documents and templates' is set to 'Enabled: Open/Save blocked, use open policy'

Information

This policy setting determines whether users can open, view, edit, or save Word 2007 and later binary documents and templates.

By choosing the Open/Save blocked, use open policy both the opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the 'default file block behavior' key.

The recommended state for this setting is: Enabled: Open/Save blocked, use open policy

By default, users can open, view, or edit this type of document in Word. This could allow malicious code to become active on a user computer or the network.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Open/Save blocked, use open policy

Microsoft Word 2016\Word Options\Security\Trust Center\File Block Settings\Word 2007 and later binary documents and templates

Impact:

Word 2007 and later binary documents and templates will not open in Microsoft Word.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3c.2.

Plugin: Windows

Control ID: 0d7b3fc294cdae2b27523747aea10d6fe2704c15fda6323446a0e247c89b2a44