2.3.27.14 (L1) Ensure 'Encryption type for password protected Office Open XML files' is set to 'Enabled'

Information

This policy setting allows for specification of an encryption type for Office Open XML files.

The chosen encryption type must have a corresponding cryptographic service provider (CSP) installed on the computer that encrypts the file.

Note: This policy setting does not take effect unless the registry key <xhtml:br/> HKEY_CURRENT_USER\Software\Microsoft\Office\16.0<office application name>\Security\Crypto\CompatMode is set to 0. By default the CompatMode registry key is set to 1.

The recommended state for this setting is: Enabled: Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256

If unencrypted files are intercepted, sensitive information in the files can be compromised. To protect information confidentiality, Office application files can be encrypted and password protected. Only users who know the correct password will be able to decrypt such files.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256 :

Microsoft Office 2016\Security Settings\Encryption type for password protected Office Open XML files

Impact:

Consider the needs of the organization and users when selecting an encryption method to enforce. If working for a government agency, contracting for a government agency, or otherwise working with very sensitive information, select a method that complies with policies that govern how such information is processed. Remember to ensure that the selected cryptographic service provider is installed on the computers of all users who need to work with password-protected Office Open XML files.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|IA-5(1), 800-53|SA-15, 800-53|SC-28, 800-53|SC-28(1)

Plugin: Windows

Control ID: 9e1cb13b4443b32ca2768cafc68ce73ba124bafd718e813f29df53c292b0d65d