STIGQter STIGQter: STIG Summary: Microsoft Excel 2013 STIG Version: 1 Release: 7 Benchmark Date: 27 Apr 2018:

Macros must be blocked from running in Office 2013 files from the Internet.

DISA Rule

SV-87483r1_rule

Vulnerability Number

V-72831

Group Title

DTOO600 - Macros must be blocked from running in Office 2013 files from the Internet.

Rule Version

DTOO600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Set the policy value for User Configuration >> Administrative Templates >> Microsoft Excel 2013 >> Excel Options >> Security >> Trust Center "Block macros from running in Office files from the Internet" to "Enabled".

Check Contents

Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Excel 2013 >> Excel Options >> Security >> Trust Center "Block macros from running in Office files from the Internet" is set to "Enabled".

Procedure: Use the Windows Registry Editor to navigate to the following key:

HKCU\Software\Policies\Microsoft\Office\15.0\excel\security

Criteria: If the value blockcontentexecutionfrominternet is REG_DWORD = 1, this is not a finding.

Vulnerability Number

V-72831

Documentable

False

Rule Version

DTOO600

Severity Override Guidance

Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Excel 2013 >> Excel Options >> Security >> Trust Center "Block macros from running in Office files from the Internet" is set to "Enabled".

Procedure: Use the Windows Registry Editor to navigate to the following key:

HKCU\Software\Policies\Microsoft\Office\15.0\excel\security

Criteria: If the value blockcontentexecutionfrominternet is REG_DWORD = 1, this is not a finding.

Check Content Reference

M

Target Key

2478

Comments