Check: DTOO139
Microsoft Excel 2016 STIG:
DTOO139
(in versions v2 r1 through v1 r1)
Title
The Save commands default file format must be configured. (Cat II impact)
Discussion
This policy setting controls the default file format for saving workbooks in Excel. If you enable this policy setting, you can set the default file format for Excel from among the following options:- Excel Workbook (.xlsx). This option is the default configuration in Excel 2016.- Excel Macro-Enabled Workbook (.xlsm)- Excel Binary Workbook (.xlsb)- Web Page (.htm; .html)- Excel 97-2003 Workbook (.xls)- Excel 5.0/95 Workbook (.xls)- OpenDocument Spreadsheet (*.ods). Users can choose to save workbooks in a different file format than the default. If you disable or you do not configure this policy setting, Excel saves new workbooks in the Office Open XML format with an .xlsx extension.
Check Content
Verify the policy value for User Configuration -> Administrative Templates -> Microsoft Excel 2016 -> Excel Options -> Save "default file format" is set to "Enabled: (Excel Workbook *.xlsx)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\16.0\excel\options Criteria: If the value DefaultFormat is REG_DWORD = 0x00000033(hex) or 51 (Decimal), this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Excel 2016 -> Excel Options -> Save "default file format" to "Enabled: (Excel Workbook *.xlsx)".
Additional Identifiers
Rule ID: SV-238182r879587_rule
Vulnerability ID: V-238182
Group Title: SRG-APP-000141
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000381 |
The organization configures the information system to provide only essential capabilities. |
Controls
Number | Title |
---|---|
CM-7 |
Least Functionality |