My security organization has responded to the threat of macro-based viruses by changing all copies of Excel to no longer run macros/VBA scripts. Through some quick research, it looks like there are many valid alternatives to the "brute orce" approach. From my limited understanding, we could:
- Establish a trusted location
- Use the Office 2016 option to block macros in Internet sourced files
- Block other Office applications than Excel
- Establish an access group that has permissions to run macros
- As above, but with permissions to run certified macros (and then certify the macro(s) needed)
All of these seem like worthwhile ways of letting our group continue working and I'm hoping the conversation will go well.
As security professionals yourselves, how would you wish a customer/user would present and participate in this discussion? Thanks very much in advance.