Back

Configure the "Disable AutoComplete for forms" setting in limited functionality environments properly.


CONTROL ID
04406
CONTROL TYPE
Configuration
CLASSIFICATION
Preventive

SUPPORTING AND SUPPORTED CONTROLS




This Control directly supports the implied Control(s):
  • Configure Internet Browser security options according to organizational standards., CC ID: 02166

There are no implementation support Controls.


SELECTED AUTHORITY DOCUMENTS COMPLIED WITH




  • This setting controls the automatic completion of form fields on Web pages. For Enterprise Client environments, the Disable AutoComplete For Forms setting is Not Configured. For Specialized Security - Limited Functionality environments, this setting should be Enabled. (Pg 100, Microsoft Windows Vista Security Guide Appendix A: Security Group Policy Settings)
  • The "Disable AutoComplete for forms" setting should be configured correctly. (oval:gov.nist.fdcc.ie7:def:1516, FDCC Windows IE7 SCAP content using OVAL (fdcc-ie7-oval.xml, fdcc-ie7-patches.xml), Version 5.4)
  • Disable AutoComplete for forms - Local User (DisableAutoCompleteForForms_LocalUser, NIST SCAP Microsoft Internet Explorer Version 7 (fdcc-ie7-xccdf.xml), FDCC IE7 (1.2) SCAP Content - OVAL 5.4)