Word 2007 STIG Version 4, Release 15 Checklist Details (Checklist Revisions)

Supporting Resources:


Target CPE Name
Microsoft Word 2007 cpe:/a:microsoft:word:2007 (View CVEs)

Checklist Highlights

Checklist Name:
Word 2007 STIG
Checklist ID:
Version 4, Release 15
Review Status:
Governmental Authority: Defense Information Systems Agency
Original Publication Date:

Checklist Summary:

This Microsoft Office Word 2007 Security Technical Implementation Guide (STIG) provides the technical security policies, requirements, and implementation details for applying security concepts to Commercial-Off-The-Shelf (COTS) applications. The nearly universal presence of systems on the desktops of all levels of staff provides tremendous opportunities for office automation, communication, data sharing, and collaboration. Unfortunately, this presence also brings about dependence and vulnerabilities. Malicious and mischievous forces have attempted to take advantage of the vulnerabilities and dependencies to disrupt the work processes of the Government. Compounding this problem is the fact that the vendors of software applications have not expended sufficient effort to provide strong security in their applications. Where applications do offer security options, the default settings typically do not provide a strong security posture. There are multiple STIG packages for Microsoft Office 2007; each contains technology-specific guidelines for the respective package along with the overall Microsoft Office System requirements. The individual packages are: ? Microsoft Access 2007 ? Microsoft Excel 2007 ? Microsoft InfoPath 2007 ? Microsoft Outlook 2007 ? Microsoft Office System 2007 ? Microsoft PowerPoint 2007 ? Microsoft Word 2007 This STIG contains security technical implementation guidance for Microsoft Office Word 2007 only.

Checklist Role:

  • Desktop Client
  • Office Software

Known Issues:

Not Provided

Target Audience:

Not Provided

Target Operational Environment:

  • Managed
  • Specialized Security-Limited Functionality (SSLF)

Testing Information:

Not Provided

Regulatory Compliance:

DOD Directive 8500.01


Not Provided


Not Provided

Product Support:

Not Provided

Point of Contact:



Not Provided


Not Provided

Change History:

Changed status from "Under Review" to "Final" - 30 December 2015
Updated URL to reflect change to the DISA website - http --> https
Sunset By DISA - 10/27/2017
Updated URLs - 6/24/19
updated URLs - 9/11/19


URL Description


Reference URL Description

NIST checklist record last modified on 09/11/2019