Home > Midmarket CIO Tips > Security for the midmarket > Securing your Office
CIO Midmarket Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY FOR THE MIDMARKET

Securing your Office


Tony Bradley, Contributor
05.18.2006
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


This tip originally appeared on SearchWindowsSecurity.com, a sister site of SearchSMB.com.

Microsoft Office is the most widely used office and productivity suite in the world. With the vast majority of users relying on Microsoft Word, Microsoft Excel and Microsoft PowerPoint for their day-to-day tasks, Microsoft Office, and the suite of programs it includes, represents an enormous target for an attacker who can find a hole to exploit.

In March of 2006, Microsoft released only two new Security Bulletins. One was rated as important and the other was critical. Critical Security Bulletin MS06-012 pertains to vulnerabilities in Microsoft Office that could allow a successful attacker to take complete control of a vulnerable system. In February 2006, a flaw, rated as important, was announced regarding PowerPoint (MS06-010).

It is imperative that users secure and protect their Microsoft Office programs as much as the operating system and Web browser they use. The overall security of the computer is only as strong as its weakest point, and Microsoft Office products could be that point. Follow these tips to lock down your Microsoft Office:

  • Make sure macro protection is on: Macros still represent a potential risk if macros from unknown or untrusted sources are executed. Macro security should be turned on to ensure macros are disabled or that the user is asked before macros are run. This has to be done on a product-by-product basis, usually from within the Options settings.
  • Patch and update your Office products: Until recently, users had to visit the Microsoft Office Web site to manually initiate a scan for new patches for Microsoft Office products. Use Automatic Updates or scan your computer from the Windows Update site using current software to identify and apply patches for both the Windows operating system and Office products as well as other Microsoft applications. Regardless of how you do it, check frequently for new patches and apply those that affect your system.
  • Follow standard computer security precautions: No matter what the attack or exploit is, common sense and computer security fundamentals are always a good idea. Ensure that your systems are protected by a firewall and have current, updated antivirus software running.
  • Remove hidden metadata: This is more of a confidentiality and privacy concern than a security issue, but most users don't realize the volume of information hidden in the background of many Microsoft Office documents, particularly Microsoft Word. Even if you delete sensitive information like credit card or social security numbers from a document, that information is retained in the hidden metadata. In the options for Microsoft Word, you can disable FastSave. You can also set the Privacy options to "Remove personal information from file properties on save." There are also tools to remove the hidden data, such as the free Remove Hidden Data add-in from Microsoft.

About the author: Tony Bradley is a consultant and writer with a focus on network security, antivirus and incident response. Bradley is the co-author of Hacker's Challenge 3 and he is the About.com Guide for Internet / Network Security providing a broad range of information security tips, advice, reviews and information. He also contributes frequently to other industry publications. For a complete list of his freelance contributions, visit S3KUR3.


Rate this Tip
To rate tips, you must be a member of SearchCIO-Midmarket.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Information security management for the midmarket
Droid does, but will IT support it?
Information security program revamp adds outsourcer oversight and more
From data breaches to risk management frameworks: Test your knowledge
The challenge of managing risk when IT budgets tighten
Why cybersecurity awareness is everyone's responsibility
Information technology management e-book downloads for midmarket CIOs
10 must-have steps for an effective SMB information security program
Your IT security budget: How to get more bang for the buck
Using key risk indicators to sell your information security program
IT security spending a bright spot in '09, with more growth predicted

Security for the midmarket
Information security program revamp adds outsourcer oversight and more
Your IT security budget: How to get more bang for the buck
Locking down security in the move to electronic medical records
A CIO's advice for implementing single sign-on solutions
Options for outsourcing security grow, offer IT budget savings
Network access control: Pointers for getting the knack of NAC
Stopping malware viruses from attacking Web 2.0 technology
Virtual servers no escape from IT security management concerns
Unified communications: Securing access to OCS
Unified communications security: How safe is it?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Mid-market CIO Business Solutions on Data Integrity, Unified Communications, and Virtualization
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2007 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts