2.2.4.7.2.2.12 (L1) Ensure 'Excel 97-2003 workbooks and templates' is set to 'Enabled: Open/Save Blocked, Use Open Policy'

Information

This policy setting determines whether users can open, view, edit, or save Excel files with Excel 97-2003 workbooks and templates file format.

Open/Save blocked, use open policy : Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the 'default file block behavior' key.

Note:

Use Open Policy

action is defined by the

Set default file block behavior

policy setting which is included in this benchmark.

The recommended state for this setting is: Enabled: Open/Save blocked, use open policy

Using legacy file formats could allow malicious code to become active on user computers or the network.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Open/Save blocked, use open policy

Microsoft Excel 2016\Excel Options\Security\Trust Center\File Block Settings\Excel 97-2003 workbooks and templates

Impact:

Users will not be able to open, save, or view Excel 97-2003 workbooks and templates.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3c.2.

Plugin: Windows

Control ID: 7ddbbcd05005f60c656e90d7cf1ef5b772cd2ff0eb45c3baae06ba1b4336ac7e