Details
Users are not required to connect to the network to verify permissions. If users do not need their licenses confirmed when attempting to open Office documents, they might be able to access documents after their licenses have been revoked. Also, it is not possible to log the usage of files with restricted permissions if users’ licenses are not confirmed.
Solution
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2013 -> Manage Restricted Permissions ‘Always require users to connect to verify permission’ to ‘Enabled’.
Supportive Information
The following resource is also helpful.
This security hardening control applies to the following category of controls within NIST 800-53: Access Control.This control applies to the following type of system Windows.
References
- 800-53|AC-6(10)
- CAT|II
- CCI|CCI-002235
- Rule-ID|SV-228556r508020_rule
- STIG-ID|DTOO201
- STIG-Legacy|SV-52750
- STIG-Legacy|V-17731
- Vuln-ID|V-228556