SV-33457r2_rule
V-17617
DTOO190 - Encr. type for Password Protected files
DTOO190 - Office System
CAT II
10
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Encryption type for password protected Office 97-2003 files” to “Enabled (Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256)”.
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Encryption type for password protected Office 97-2003 files” must be set to “Enabled (Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256)”.
Procedure: Use the Windows Registry Editor to navigate to the following key:
HKCU\Software\Policies\Microsoft\Office\14.0\common\security
Criteria: If the value DefaultEncryption12 is REG_SZ = “Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256", this is not a finding.
V-17617
False
DTOO190 - Office System
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Encryption type for password protected Office 97-2003 files” must be set to “Enabled (Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256)”.
Procedure: Use the Windows Registry Editor to navigate to the following key:
HKCU\Software\Policies\Microsoft\Office\14.0\common\security
Criteria: If the value DefaultEncryption12 is REG_SZ = “Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256", this is not a finding.
M
Information Assurance Officer
2105