2.3.27.13 Ensure 'Encryption type for password protected Office 97-2003 files' is set to 'Enabled'

Information

This policy setting enables specification of an encryption type for password-protected Office 97-2003 files.

The recommended state for this setting is: Enabled: Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256.

Rationale:

If unencrypted files are intercepted, sensitive information in the files can be compromised. To protect information confidentiality, Microsoft Office application files can be encrypted and password protected. Only users who know the correct password will be able to decrypt such files.

Impact:

Consider the needs of the organization and users when selecting an encryption method to enforce. If working for a government agency, contracting for a government agency, or otherwise working with very sensitive information, select a method that complies with policies that govern how such information is processed. Remember to ensure that the selected cryptographic service provider is installed on the computers of all users who need to work with password-protected Office 97-2003 files.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256:

User Configuration\Administrative Templates\Microsoft Office 2016\Security Settings\Encryption type for password protected Office 97-2003 files

Default Value:

Excel, PowerPoint, and Word use Office 97/2000 Compatible encryption, a proprietary encryption method, to encrypt password-protected Office 97-2003 files.

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|IA-5(1), 800-53|SA-15, 800-53|SC-28, 800-53|SC-28(1)

Plugin: Windows

Control ID: 925c9190b8035e9333ce45d53a304dface1bbe6cc05f6ff63690646d01a3a158