Check: DTBI690
Microsoft Internet Explorer 9 STIG:
DTBI690
(in version v1 r15)
Title
AutoComplete feature for forms must be disallowed. (Cat II impact)
Discussion
This AutoComplete feature suggests possible matches when users are filling in forms. If you enable this setting, the user is not suggested matches when filling forms. The user cannot change it. If you disable this setting, the user is suggested possible matches when filling forms. The user cannot change it. If you do not configure this setting, the user has the freedom to turn on the auto-complete feature for forms. To display this option, the users open the Internet Options dialog box, click the Contents Tab and click the Settings button.
Check Content
The policy value for User Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> "Disable AutoComplete for forms" must be “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Internet Explorer\Main Criteria: If the value Use FormSuggest is REG_SZ = no, this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> "Disable AutoComplete for forms" to “Enabled”.
Additional Identifiers
Rule ID: SV-40691r1_rule
Vulnerability ID: V-15574
Group Title: DTBI690 - AutoComplete for forms
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |