Microsoft releases new security guide for Office 2007

In an effort to help Microsoft Office users remain productive and keep data secure, Microsoft has released a new document, 2007 Microsoft Office Security Guide, designed to help defeat attacks that target e-mail and desktop documents. The guide offers detailed documentation for securing Office 2007 applications to protect against specially written document files with malicious code hidden within them.

It is an unfortunate fact that e-mail attachments, macros, and add-ins can contain viruses or other malware. The 2007 Microsoft Office Security Guide provides IT professionals with best practices and automated tools to help strengthen the security of computers that run either Windows Vista or Windows XP SP2 as well as the following applications:

  • Microsoft Office Access 2007

  • Microsoft Office Excel 2007

  • Microsoft Office InfoPath 2007

  • Microsoft Office Outlook 2007

  • Microsoft Office PowerPoint 2007

  • Microsoft Office Word 2007

    The 2007 Microsoft Office Security Guide consists of the following components:

  • Executive Overview. This document summarizes for business and technical managers how the guidance and tools in this Solution Accelerator can benefit your organization.

  • Security Guide. This guide describes the security model for the 2007 Microsoft Office release as well as new security features and functionality. It includes recommended guidelines and best practices for implementing security settings for two different environments—an Enterprise Client (EC) environment, which seeks to balance functionality and security and is appropriate for most organizations, and the Specialized Security – Limited Functionality (SSLF) environment, which is only appropriate for organizations that require very strong security at the expense of application functionality. SSLF settings restrict some application features.

  • Threats and Countermeasures. This guide is a comprehensive technical reference that explains the security and privacy settings for the six referenced applications, their recommended configurations, and which threats they address. It also contains Common Configuration Enumeration (CCE) IDs for all the settings. CCE provides identifiers to system configurations to facilitate fast and accurate correlation of configuration data across multiple information sources and tools.

  • Security Settings spreadsheet. This Office Excel spreadsheet lists security settings for the six referenced applications and their recommended configurations for the EC and SSLF environments, as well as Common Configuration Enumeration (CCE) IDs for all the settings.

  • GPOAccelerator. This tool helps you automatically deploy security configurations for the 2007 Microsoft Office release across your organization. It can also be used to deploy security settings for Windows® XP and Windows Vista.

    The Office 2007 Security Guide will be formally introduced at the Microsoft TechEd conference this week in Barcelona, Spain. The guide will offer detailed documentation for securing Office 2007 applications to protect against specially written document files with malicious code hidden within them.

    You can access the 2007 Microsoft Office Security Guide.

    You may like these other stories...

    Regulatory compliance, risk management and cost-cutting are the big heartburn issues for finance execs in the C-suite. Yet financial planning and analysis—a key antacid—is insufficient.That's just one of the...
    Continuing its efforts to simplify accounting procedures, the FASB has issued a proposed Accounting Standards Update on customer fees paid in a cloud computing arrangement. The newly-proposed update (Intangibles—...
    How are you planning? What tools do you use (or fail to use) for forecasting? PlanGuru is a business budgeting, forecasting, and performance review software company based in White Plains, N.Y. AccountingWEB recently spoke...

    Already a member? log in here.

    Upcoming CPE Webinars

    Sep 9
    In this session we'll discuss the types of technologies and their uses in a small accounting firm office.
    Sep 10
    Transfer your knowledge and experience to prepare your team for the challenges and opportunities of an accounting career.
    Sep 11
    This webcast will include discussions of commonly-applicable Clarified Auditing Standards for audits of non-public, non-governmental entities.
    Sep 26
    In this jam-packed presentation Excel expert David Ringstrom, CPA will give you a crash-course in creating spreadsheet-based dashboards. A dashboard condenses large amounts of data into a compact space, yet enables the end user to easily drill down into details when warranted.