DTOO201 - Office System - Connection verification of permissions must be enforced.

Information

Users are not required to connect to the network to verify permissions. If users do not need their licenses confirmed when attempting to open Office documents, they might be able to access documents after their licenses have been revoked. Also, it is not possible to log the usage of files with restricted permissions if users' licenses are not confirmed.

Solution

Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Manage Restricted Permissions 'Always require users to connect to verify permission' to 'Enabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_OfficeSystem_2010_V1R12_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(10), CAT|II, CCI|CCI-002235, Rule-ID|SV-33460r1_rule, STIG-ID|DTOO201, Vuln-ID|V-17731

Plugin: Windows

Control ID: 1f54f2756930d620e4084fb8e6d9f375589c3e748c5893bfbc8ab4606e6eb5ff