Details
This policy setting allows you to specify an encryption type for Office Open XML files. If you enable this policy setting, you can specify the type of encryption that Office applications use to encrypt password-protected files in the Office Open XML file formats used by Excel, PowerPoint, and Word. The chosen encryption type must have a corresponding cryptographic service provider (CSP) installed on the computer that encrypts the file. See the HKEY_LOCAL_MACHINESOFTWAREMicrosoftCryptographyDefaultsProvider registry key for a list of CSPs installed on the local computer. Specify the encryption type to use by entering it in the provided text box in the following form:
Solution
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2016 -> Security Settings ‘Encryption type for password protected Office Open XML files’ to ‘Enabled (Microsoft Enhanced RSA and AES Cryptographic Provider,AES 256,256)’.
Supportive Information
The following resource is also helpful.
This security hardening control applies to the following category of controls within NIST 800-53: System and Communications Protection.This control applies to the following type of system Windows.
References
- 800-53|SC-28
- CAT|II
- CCI|CCI-001199
- Rule-ID|SV-238028r650651_rule
- STIG-ID|DTOO189
- STIG-Legacy|SV-85489
- STIG-Legacy|V-70865
- Vuln-ID|V-238028