2.2.4.7.2.3.4 (L1) Ensure 'Set document behavior if file validation fails' is set to 'Enabled: Open in Protected View'

Information

This policy setting controls how Office handles documents when they fail file validation.

Office File Validation is a feature that performs security checks on files. If Office File Validation detects a problem with a file, the file cannot be opened.

The recommended state for this setting is: Enabled: Open in Protected View

Files that have failed file validation outside of Protected View could allow malicious code to execute on the system or the network.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Open in Protected View

Microsoft Excel 2016\Excel Options\Security\Trust Center\Protected View\Set document behavior if file validation fails

Impact:

Files that are blocked by the validation fail rule will not open on a user's computer.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4)

Plugin: Windows

Control ID: 63c2258b5048eac12b14b4c315854789af15b65001b0865587c761144b8a3390