Microsoft Office 2007 Overview Version 4, Release 14 Checklist Details (Checklist Revisions)
NOTE
This is not the current revision of this Checklist, view the current revision.
Supporting Resources:
-
Download Standalone XCCDF 1.1.4 - Microsoft Office 2007 STIG, Version 4, Release 7
- Defense Information Systems Agency
Target:
Target | CPE Name |
---|---|
Microsoft Access 2007 | cpe:/a:microsoft:access:2007 (View CVEs) |
Microsoft Excel 2007 | cpe:/a:microsoft:excel:2007 (View CVEs) |
Microsoft Infopath 2007 | cpe:/a:microsoft:infopath:2007 (View CVEs) |
Microsoft Office 2007 | cpe:/a:microsoft:office:2007 (View CVEs) |
Microsoft Outlook 2007 | cpe:/a:microsoft:outlook:2007 (View CVEs) |
Microsoft PowerPoint 2007 | cpe:/a:microsoft:powerpoint:2007 (View CVEs) |
Microsoft Visio 2007 | cpe:/a:microsoft:visio:2007 (View CVEs) |
Microsoft Word 2007 | cpe:/a:microsoft:word:2007 (View CVEs) |
Checklist Highlights
- Checklist Name:
- Microsoft Office 2007 Overview
- Checklist ID:
- 339
- Version:
- Version 4, Release 14
- Type:
- Compliance
- Review Status:
- Final
- Authority:
- Governmental Authority: Defense Information Systems Agency
- Original Publication Date:
- 04/29/2011
Checklist Summary:
This Microsoft Office Technology Overview, along with the associated Security Technical Implementation Guide (STIG), provides the technical security policies, requirements, and implementation details for applying security concepts to Commercial-Off-The-Shelf (COTS) applications. The nearly universal presence of systems on the desktops of all levels of staff provides tremendous opportunities for office automation, communication, data sharing, and collaboration. Unfortunately, this presence also brings about dependence and vulnerabilities. Malicious and mischievous forces have attempted to take advantage of the vulnerabilities and dependencies to disrupt the work processes of the Government. Compounding this problem is the fact that the vendors of software applications have not expended sufficient effort to provide strong security in their applications. Where applications do offer security options, the default settings typically do not provide a strong security posture.
Checklist Role:
- Office Software
Known Issues:
Not provided.
Target Audience:
Developed for the DOD. This checklist has been created for IT professionals, particularly Windows system administrators and information security personnel. The document assumes that the reader has experience installing and administering applications on Windows-based systems in domain or standalone configurations.
Target Operational Environment:
- Managed
- Specialized Security-Limited Functionality (SSLF)
Testing Information:
Not provided.
Regulatory Compliance:
DOD Directive 8500.
Comments/Warnings/Miscellaneous:
All Microsoft Office 2007 users who are consuming the provided SCAP content must first run the Microsoft Office System 2007 SCAP Content which provides generic Office checks. Then the user should run the SCAP bundle for each Microsoft Office product running on the user's systems.
Disclaimer:
Not provided.
Product Support:
Not provided.
Point of Contact:
NIST - checklists@nist.gov
Sponsor:
Not provided.
Licensing:
Not provided.
Change History:
Version 4, Release 7 - 04/27/2012 Version 4, Release 6 - 01/26/2012 Version 4, Release 5 - 07/29/2011 Version 4, Release 4 - 04/29/2011 Version 4, Release 3 - 01/28/2011 Version 4, Release 2 - 08/27/2010 Version 4, Release 1 - 12/09/2009
Dependency/Requirements:
URL | Description |
---|---|
http://scap.nist.gov/revision/1.0/index.html#tools | This is a link to the SCAP Content Validation Tool designed to validate SCAP 1.0 source content. |
References:
Reference URL | Description |
---|