Home > Data management / BI News > Securing your Office
Data management / BI News:
EMAIL THIS

Securing your Office

By Tony Bradley, Contributor
18 May 2006 | SearchWindowsSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Microsoft Office is the most widely used office and productivity suite in the world. With the vast majority of users relying on Microsoft Word, Microsoft Excel and Microsoft PowerPoint for their day-to-day tasks, Microsoft Office, and the suite of programs it includes, represents an enormous target for an attacker who can find a hole to exploit.

In March of 2006, Microsoft released only two new Security Bulletins. One was rated as important and the other was critical. Critical Security Bulletin MS06-012 pertains to vulnerabilities in Microsoft Office that could allow a successful attacker to take complete control of a vulnerable system. In February 2006, a flaw, rated as important, was announced regarding PowerPoint (MS06-010).

It is imperative that users secure and protect their Microsoft Office programs as much as the operating system and Web browser they use. The overall security of the computer is only as strong as its weakest point, and Microsoft Office products could be that point. Follow these tips to lock down your Microsoft Office:

  • Make sure macro protection is on: Macros still represent a potential risk if macros from unknown or untrusted sources are executed. Macro security should be turned on to ensure macros are disabled or that the user is asked before macros are run. This has to be done on a product-by-product basis, usually from within the Options settings.
  • Patch and update your Office products: Until recently, users had to visit the Microsoft Office Web site to manually initiate a scan for new patches for Microsoft Office products. Use Automatic Updates or scan your computer from the Windows Update site using current software to identify and apply patches for both the Windows operating system and Office products as well as other Microsoft applications. Regardless of how you do it, check frequently for new patches and apply those that affect your system.
  • Follow standard computer security precautions: No matter what the attack or exploit is, common sense and computer security fundamentals are always a good idea. Ensure that your systems are protected by a firewall and have current, updated antivirus software running.
  • Remove hidden metadata: This is more of a confidentiality and privacy concern than a security issue, but most users don't realize the volume of information hidden in the background of many Microsoft Office documents, particularly Microsoft Word. Even if you delete sensitive information like credit card or social security numbers from a document, that information is retained in the hidden metadata. In the options for Microsoft Word, you can disable FastSave. You can also set the Privacy options to "Remove personal information from file properties on save." There are also tools to remove the hidden data, such as the free Remove Hidden Data add-in from Microsoft.

About the author: Tony Bradley is a consultant and writer with a focus on network security, antivirus and incident response. Bradley is the co-author of Hacker's Challenge 3 and he is the About.com Guide for Internet / Network Security providing a broad range of information security tips, advice, reviews and information. He also contributes frequently to other industry publications. For a complete list of his freelance contributions, visit S3KUR3.



Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Data Management: Business Intelligence, Data Integration, Data Compliance
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2005 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts