National Vulnerability Database

National Vulnerability Database

National Vulnerability

Microsoft Office System 2016 STIG Version 1, Release 1 Checklist Details (Checklist Revisions)

Supporting Resources:


Target CPE Name
Microsoft Office 2016 cpe:/a:microsoft:outlook:2016 (View CVEs)

Checklist Highlights

Checklist Name:
Microsoft Office System 2016 STIG
Checklist ID:
Version 1, Release 1
Review Status:
Governmental Authority: Defense Information Systems Agency
Original Publication Date:

Checklist Summary:

The Microsoft Office 2016 Security Technical Implementation Guides (STIGs) provide the technical security policies, requirements, and implementation details for applying security concepts to Office 2016 applications. These documents are meant to improve the security of Department of Defense (DoD) information systems. There are multiple STIG packages for Microsoft Office 2016, each contains technology-specific guidelines for the respective package. The Microsoft Office System 2016 STIG must also be applied when any Office 2016 package is installed. The individual packages are: • Microsoft Access 2016 • Microsoft Excel 2016 • Microsoft Office System 2016 • Microsoft OneDrive for Business 2016 • Microsoft OneNote 2016 • Microsoft Outlook 2016 • Microsoft PowerPoint 2016 • Microsoft Project 2016 • Microsoft Publisher 2016 • Microsoft Skype for Business 2016 • Microsoft Visio 2016 • Microsoft Word 2016

Checklist Role:

  • Desktop Client
  • Office Software

Known Issues:

Not provided.

Target Audience:

Developed for the DOD. This checklist has been created for IT professionals, particularly Windows system administrators and information security personnel. The document assumes that the reader has experience installing and administering applications on Windows-based systems in domain or standalone configurations.

Target Operational Environment:

  • Managed
  • Specialized Security-Limited Functionality (SSLF)

Testing Information:

Not provided.

Regulatory Compliance:

DOD Directive 8500.1


Not provided.


Not provided.

Product Support:

Not provided.

Point of Contact:


Not provided.


Not provided.

Change History:

Updated to FINAL - 02/23/2017
Updated URL to reflect change to the DISA website - http --> https
updated benchmark to v1,r2 - 4/25/18
Corrected Title - 5/9/18
corrected resource title - 5/24/18
corrected benchmark - 5/24/18
Update to FINAL - 5/25/18
Added GPOs - 8/6/18
Updated to FINAL - 9/6/2018
Updated benchmark - 10/25/18
Updated to FINAL - 11/26/18
Updated GPO Resource - 11/29/2018
Corrected SHA for GPO file - 12/19/2018
updated GPO file - 2/8/19
Status Updated to FINAL - 3/8/19
Updated URLs - 6/7/19
Removed Unsupported Content Link 8/30/2019


URL Description Microsoft Office 2016 STIGs Release Memo Microsoft Office 2016 STIGs Overview - Ver 1, Rel 2


Reference URL Description

NIST checklist record last modified on 08/30/2019