2.3.27.18 Ensure 'Protect document metadata for rights managed Office Open XML Files' is set to 'Enabled'

Information

This policy setting determines whether metadata is encrypted in Office Open XML files that are protected by Information Rights Management (IRM).

The recommended state for this setting is: Enabled.

Rationale:

By default, when Information Rights Management (IRM) is used to restrict access to an Office Open XML document, any metadata associated with the document is not encrypted. This configuration could allow potentially sensitive information such as the document author and hyperlink references to be exposed to unauthorized people.

Impact:

Enabling this setting might interfere with the functioning of tools that aggregate and display metadata information for Office Open XML files, but is otherwise unlikely to cause significant usability issues.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

User Configuration\Administrative Templates\Microsoft Office 2016\Security Settings\Protect document metadata for rights managed Office Open XML Files

Default Value:

Disabled. (Metadata associated with IRM restricted documents is not encrypted.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|IA-5(1), 800-53|SC-28, 800-53|SC-28(1)

Plugin: Windows

Control ID: 5e52f9d3532fc5ff833d89a4f7eb08c04772898576cb4938f33df83ad685f1c6